gegl-0.2.0-40.el8_10

エラータID: AXSA:2026-1336:01

Release date: 
Thursday, July 23, 2026 - 17:33
Subject: 
gegl-0.2.0-40.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

GEGL (Generic Graphics Library) is a graph-based image processing framework.

Security Fix(es):

* gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing (CVE-2026-2050)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-2050
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28266.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gegl-0.2.0-40.el8_10.src.rpm
    MD5: 1dac273c3ec1eca8309c48ffaf0076d0
    SHA-256: 3cbf0cf5f02b0d69e9170ac91786355563ea94cb5728be00b6387e982a2d8585
    Size: 7.19 MB

Asianux Server 8 for x86_64
  1. gegl-0.2.0-40.el8_10.i686.rpm
    MD5: 7974b460ade5be4ec83df3041768a217
    SHA-256: 3878c0da201ffe547b22a15e249a78cb7a698f6c608741515d15a576e44301ff
    Size: 825.00 kB
  2. gegl-0.2.0-40.el8_10.x86_64.rpm
    MD5: 041f6e2275f9a4960232d78860cdef6c
    SHA-256: fa5d189821e68df4416b457481fae9fff48b01ba9ff50982b678075d0880ec89
    Size: 798.48 kB