gimp-3.0.4-4.el9_8.9
エラータID: AXSA:2026-1618:09
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.
Security Fix(es):
* gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c) (CVE-2026-42169)
* gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images (CVE-2026-66758)
* gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images (CVE-2026-66759)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42169
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.
CVE-2026-66758
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
CVE-2026-66759
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
Update packages.
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
N/A
SRPMS
- gimp-3.0.4-4.el9_8.9.src.rpm
MD5: bf4be577444d87eb0951959a42693267
SHA-256: 3c9bb5e6cd1aed4cca439db45ea019228d21e8e7a760c3e6467cdc20264bdefc
Size: 25.89 MB
Asianux Server 9 for x86_64
- gimp-3.0.4-4.el9_8.9.x86_64.rpm
MD5: 8e0de185dc8ee4bbf0addaccf196b5cc
SHA-256: daecca014b5bb01e2ae0ceb590bee5b88a43b66f71aaebc79f0481bf7fb3fd62
Size: 20.91 MB - gimp-libs-3.0.4-4.el9_8.9.i686.rpm
MD5: 458bbabd746251755fc79dc21325d8f8
SHA-256: 1b093988d6f838609b13862e72d708a6ed0eec528289c551ee505ca7438e77d5
Size: 851.54 kB - gimp-libs-3.0.4-4.el9_8.9.x86_64.rpm
MD5: 187f48a6ec32ba52e63fa5513fe5054c
SHA-256: b0cb9b5b76e5f5c9183f0dbe4f88ce6ad850d9f17e269612e793adc600ba019e
Size: 804.23 kB