gimp-3.0.4-4.el9_8.5

エラータID: AXSA:2026-1494:07

Release date: 
Friday, August 7, 2026 - 21:47
Subject: 
gimp-3.0.4-4.el9_8.5
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

* gimp: gimp: Heap buffer overflow in read_channel_data() (CVE-2026-58379)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-58379
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an overwrite of adjacent memory.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gimp-3.0.4-4.el9_8.5.src.rpm
    MD5: 1259e14cccb61979d63e5802de69ff5d
    SHA-256: 506290ff74bd74aa9379bc2e4028bc9ca186bea454485bfe73552b960a29c75b
    Size: 25.88 MB

Asianux Server 9 for x86_64
  1. gimp-3.0.4-4.el9_8.5.x86_64.rpm
    MD5: ab31929b55e24a24251498d8563a64b2
    SHA-256: 15e9991f504c9a674639921c611306a6dab968bd009773dedd0f80d96c96cf1d
    Size: 20.92 MB
  2. gimp-libs-3.0.4-4.el9_8.5.i686.rpm
    MD5: c58b289f772baaca5285a94458c5b2c8
    SHA-256: 65927ed1e228d2194a4e7ad6540f611e2ef20d39205043bd430ec59035dccca1
    Size: 851.05 kB
  3. gimp-libs-3.0.4-4.el9_8.5.x86_64.rpm
    MD5: e4efe2ff0491ec26e53374699a24ccca
    SHA-256: 75ed1abfec957f3bd8c65e4a1d1bbc7daa6f04e4ab798d8d6de3de445fe238de
    Size: 803.07 kB