[CLSA-2026:1785922090] gimp: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-07 13:34:49 UTC
Description:
- CVE-2026-2271: validate the Creator-block field length in the PSP loader; read_creator_block() used a 32-bit length straight from the file for allocation, so a length of 0xFFFFFFFF made g_malloc(len+1) wrap to g_malloc(0) and the following read overflowed the heap
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els14.x86_64.rpm
    sha:42d44c1aa0cd404327942f2edb769a4617293a280f9da7f9e1d7e4359a3a55c9
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els14.x86_64.rpm
    sha:e8dd761dc07019234dd6682d33d3ec0681250832fb35ba93fb3dc95a44a8c6b5
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els14.x86_64.rpm
    sha:0c678cdc498788cfb9a10e8a3b7c4c26077c987acd932630867c54f8ae39eebc
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els14.i686.rpm
    sha:45fb48d0bafe047d99029cb7fe4ed83b787861446c1304a79915755f720e3db6
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els14.x86_64.rpm
    sha:0484b13fef6b7d0338d4a1442ba7c3360a64364b8bc032634acc9aa16ed8fa7f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.