gimp-3.0.4-4.el9_8.7
エラータID: AXSA:2026-1507:08
リリース日:
2026/08/11 Tuesday - 02:30
題名:
gimp-3.0.4-4.el9_8.7
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- GIMP の PNM ファイルの解析処理には、オフバイワンエラーの問題が
あるため、ローカルの攻撃者により、情報の漏洩、データ破壊、および
サービス拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-58380)
- GIMP の PSD ファイルの解析処理には、整数オーバーフローの問題が
あるため、ローカルの攻撃者により、情報の漏洩、データ破壊、および
サービス拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-58384)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-58380
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-58384
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
追加情報:
N/A
ダウンロード:
SRPMS
- gimp-3.0.4-4.el9_8.7.src.rpm
MD5: cfeca4ee7b74a5cf944a231f588f93f6
SHA-256: 1c4847797a9c7ce88fc1e612e966a7932abf57d37fc663d74d7e1e5797b3d783
Size: 25.88 MB
Asianux Server 9 for x86_64
- gimp-3.0.4-4.el9_8.7.x86_64.rpm
MD5: fca7ca0c4875b4ba0c2d83a074fcfe46
SHA-256: 19ed701ac82d22d7fd12d857253e0cb5ac23c9f6ff16cfa5c89edd3690c8c065
Size: 20.92 MB - gimp-libs-3.0.4-4.el9_8.7.i686.rpm
MD5: 8ef513a45cf40053bddb604c05299509
SHA-256: 4d0b4414d2a3b16e0df95ff394a643f5b8510566c75b54b73ca689be9a4b507e
Size: 850.97 kB - gimp-libs-3.0.4-4.el9_8.7.x86_64.rpm
MD5: 9a4ebb6d2149a0b1bd59bfc30e835524
SHA-256: 63caf4f3d03cd41e551e3e9ee154d008476fadd8b669b2d6f33df341a95b2c7f
Size: 803.08 kB