[security - high] gimp:2.8 security update

エラータID: AXSA:2026-1773:01

Release date: 
Friday, September 4, 2026 - 19:34
Subject: 
[security - high] gimp:2.8 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

* gimp: gimp: Stack buffer overflow in pnmscanner_gettoken() (CVE-2026-58380)
* gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images (CVE-2026-66758)
* gimp: GIMP: Arbitrary code execution via crafted TIF file parsing (CVE-2026-18304)
* gimp: GIMP: Remote code execution via PSD file parsing integer overflow (CVE-2026-18301)
* gimp: GIMP: Remote Code Execution via TIF file parsing integer overflow (CVE-2026-18305)
* gimp: GIMP: Remote code execution via TIF file parsing vulnerability (CVE-2026-18303)
* gimp: GIMP: Remote Code Execution via SGI File Parsing Integer Overflow (CVE-2026-18306)
* gimp: GIMP: Remote code execution via TIF file parsing heap-based buffer overflow (CVE-2026-18307)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-18301
GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29395.
CVE-2026-18303
GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29399.
CVE-2026-18304
GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29403.
CVE-2026-18305
GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29406.
CVE-2026-18306
GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SGI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29396.
CVE-2026-18307
GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29404.
CVE-2026-58380
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-66758
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Modularity name: "gimp"
Stream name: "2.8"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. gimp-2.8.22-26.module+el8+2038+b9900121.8.src.rpm
    MD5: 2498193bb4cf14ae3180141bcda588d0
    SHA-256: b2578900a419bc51d7f253a5e4538da5a53a938d622ee3875a677d9f6efd4cc3
    Size: 20.08 MB
  2. pygobject2-2.28.7-5.module+el8+2038+b9900121.src.rpm
    MD5: 3030fb45d9f941d67e33f18b9dae97ac
    SHA-256: 0a580db78e893bfb10e3ae689eb8c22bc9c48b459f2379795606aa5ac657d35b
    Size: 750.83 kB
  3. pygtk2-2.24.0-25.module+el8+2038+b9900121.src.rpm
    MD5: 2e062dfdd79f39d9625363a87dd55b5e
    SHA-256: c3530f4683bf4363d66a8c998be7d62079744f2dc0cd1074c6fccc0637635ce5
    Size: 2.28 MB
  4. python2-pycairo-1.16.3-7.module+el8+2038+b9900121.src.rpm
    MD5: 89fcb50d05b7f85ea60d583b9bc29edf
    SHA-256: 1f2655279c8c784d5f0b6b39be6be7933585f2eda17b97a531f77870b6f4c8bd
    Size: 199.60 kB

Asianux Server 8 for x86_64
  1. gimp-2.8.22-26.module+el8+2038+b9900121.8.x86_64.rpm
    MD5: 096d250309742d47d5158564e5ef48ed
    SHA-256: c64d33e5cde5f3e8546e654eb2abd0f09530aadf9b6232711702e050f98d3e09
    Size: 14.96 MB
  2. gimp-debugsource-2.8.22-26.module+el8+2038+b9900121.8.x86_64.rpm
    MD5: 5ba20e5eea50e56bc0ec02489d49ea30
    SHA-256: d6a558ecec98ba8c4b8b1fb3619bf155490d4da51c0c75298af1680b654e7815
    Size: 4.51 MB
  3. gimp-devel-2.8.22-26.module+el8+2038+b9900121.8.x86_64.rpm
    MD5: c7b4c672e24335f502f5decff0deb611
    SHA-256: 49cf4fc6b4404de3a6dd46b6da658e998870c44e2e8203564cf503d554fe9d4b
    Size: 940.87 kB
  4. gimp-devel-tools-2.8.22-26.module+el8+2038+b9900121.8.x86_64.rpm
    MD5: 92a1ebc92752e4075f506a407b345da4
    SHA-256: bd174e8b8a017ff49a093fea0e1939249f887d2b8f7a368efb9e2b3de027a56c
    Size: 79.79 kB
  5. gimp-libs-2.8.22-26.module+el8+2038+b9900121.8.x86_64.rpm
    MD5: 9855ccb46f3dcb94e9732e73ae8ed9ab
    SHA-256: a401d5682669955ee71206713e1174f36390d9a05ed90474780b76d6bfafa690
    Size: 1.40 MB
  6. pygobject2-2.28.7-5.module+el8+2038+b9900121.x86_64.rpm
    MD5: faf0735b3ff6c5fc7a878be359d43a2b
    SHA-256: 0527be689eeb1f7a31699c4a7b6f3ca45bcc045f917c305767316568fc54afc8
    Size: 235.13 kB
  7. pygobject2-codegen-2.28.7-5.module+el8+2038+b9900121.x86_64.rpm
    MD5: 5fea5d5d3132f97c75192d67a2eca2e3
    SHA-256: d073f2f2666bd94c6fef3c035ad428a0009a2b694a8501b0e9bd8cbecf7f2fc4
    Size: 108.40 kB
  8. pygobject2-debugsource-2.28.7-5.module+el8+2038+b9900121.x86_64.rpm
    MD5: b8ccad25782e62ff5174445278d36d79
    SHA-256: add011cf7b4c1c4c0d5a871e9d93a53857a77db8df8c6b50290a2a7b24e8efa5
    Size: 156.13 kB
  9. pygobject2-devel-2.28.7-5.module+el8+2038+b9900121.x86_64.rpm
    MD5: 1f981c90e10c848e4e33813cee5e050f
    SHA-256: bf825fb71dad9a21969de9a34f92afac26a98a5af2e0eca5060bdc0fb2fb9b44
    Size: 71.83 kB
  10. pygobject2-doc-2.28.7-5.module+el8+2038+b9900121.x86_64.rpm
    MD5: a6032bbd8c6d5a3088cffd97bc2810e3
    SHA-256: b33e5ca179be5a71709b3d12db4b20829a64b582c5725bda732a315f4ff9243d
    Size: 129.60 kB
  11. pygtk2-2.24.0-25.module+el8+2038+b9900121.x86_64.rpm
    MD5: 1353173135a67ead929fdc28b4ce474d
    SHA-256: 5ba1eb6dbd778f888ee7a3d2c16a92a3b9cd2b90141cb153117b06d17650424c
    Size: 928.62 kB
  12. pygtk2-codegen-2.24.0-25.module+el8+2038+b9900121.x86_64.rpm
    MD5: ed15bf8ecfdf497c45505d87d11d0879
    SHA-256: cfbccb77d909971a22e924e6f5e776166307a198ffb471dfd3ee389ce86e8a5f
    Size: 22.19 kB
  13. pygtk2-debugsource-2.24.0-25.module+el8+2038+b9900121.x86_64.rpm
    MD5: 806bd68fd28effa46e37b6faa8d7f900
    SHA-256: fca0b894053096b5323a7a8e25bf88faae2aad50258eb1a9f4d730c226aa32dc
    Size: 464.88 kB
  14. pygtk2-devel-2.24.0-25.module+el8+2038+b9900121.x86_64.rpm
    MD5: cc8a270d0b986a64b35691a06604b690
    SHA-256: 1ad5858c3c2ee2c2a1216cbad9ba0997520fa456da66191674e8a32cb812e5d7
    Size: 151.10 kB
  15. pygtk2-doc-2.24.0-25.module+el8+2038+b9900121.noarch.rpm
    MD5: a420805d8866be0b334ae3d1d953ea94
    SHA-256: 9e9f05056f3647c0dc836119b0ea3230dd197e0a06b2a9d7b39821ff0300d604
    Size: 1.19 MB
  16. python2-cairo-1.16.3-7.module+el8+2038+b9900121.x86_64.rpm
    MD5: 5ae08cc67ce3b1d1d97febe486337198
    SHA-256: 10f79a680c6ae59d17233d8afa604e56084f42cd88ef83b132a0ee60fc6ba8cb
    Size: 88.66 kB
  17. python2-cairo-devel-1.16.3-7.module+el8+2038+b9900121.x86_64.rpm
    MD5: 4b354561869a4f7e6bbb84c22b7df49b
    SHA-256: 8287d7e1182fce5166cab9e4c33f72da7727d33c3a4ebe5ed1199b304ed957b1
    Size: 15.97 kB
  18. python2-pycairo-debugsource-1.16.3-7.module+el8+2038+b9900121.x86_64.rpm
    MD5: ca23b4f780122ba6c6beea1a2c2e7640
    SHA-256: a5258c483bd31a41f18603f806a52dc576e39961349dff785e5ab2d9d2fe6e02
    Size: 55.97 kB