gegl04-0.4.62-1.el9_8.1
エラータID: AXSA:2026-1690:01
GEGL (Generic Graphics Library) is a graph-based image processing framework.
Security Fix(es):
* gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing (CVE-2026-2050)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-2050
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28266.
Update packages.
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28266.
N/A
SRPMS
- gegl04-0.4.62-1.el9_8.1.src.rpm
MD5: 48e7835a0418aeb9627eb9fa21f091ff
SHA-256: 65429f920ef3cc86e58efe422ce06587a1ece2668f64a4e6ffeee37880d0da9a
Size: 5.76 MB
Asianux Server 9 for x86_64
- gegl04-0.4.62-1.el9_8.1.i686.rpm
MD5: 16b13b86220c5a10797bea824446d644
SHA-256: 7998a283e48214c19a4a0bced4364aff6a8a1398e8405d8294bbdc43a31c3ee7
Size: 2.37 MB - gegl04-0.4.62-1.el9_8.1.x86_64.rpm
MD5: 1034f6799aaa512db78a4eae518118b7
SHA-256: 22c930301a4a7e8a3eb2267c954ea92eacd2e2e4841cf53ddb559e20a22f0cc2
Size: 2.61 MB - gegl04-devel-0.4.62-1.el9_8.1.i686.rpm
MD5: d907c9fefc49b7e016c9ac4fd158b08d
SHA-256: 2152177e7a40f9b51e53dc0d7e73bf352dc81e207ef4b42787260a71f62b5912
Size: 214.46 kB - gegl04-devel-0.4.62-1.el9_8.1.x86_64.rpm
MD5: 5d5775e64221b919bbe8c35693dc4af5
SHA-256: 4553ec3a2cad2ace661d51d3ca34ba37e86683634ec114ac6ee6be3c2ccacb3d
Size: 214.34 kB - gegl04-devel-docs-0.4.62-1.el9_8.1.x86_64.rpm
MD5: 8375b72dd718c1db504b1b5e271affcb
SHA-256: 40b1cebc5051c6ee3733fa54653a2929853755c13ebf70c1bd55041db38ec8a7
Size: 95.56 kB - gegl04-tools-0.4.62-1.el9_8.1.x86_64.rpm
MD5: bae8123dbdff7b6c14c3185c787bc5d8
SHA-256: 63f8164bfc34fa77168bff7dd8788c3611336d93d2838a81f81c9c002aa8ce41
Size: 35.84 kB