Issued at: 2026-09-02
Updated at: 2026-09-03
Advisory content derived from Red Hat RHSA-2026:62507, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: gimp:2.8 security update
Description
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.
Security Fix(es):
* gimp: gimp: Stack buffer overflow in pnmscanner_gettoken() (CVE-2026-58380)
* gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images (CVE-2026-66758)
* gimp: GIMP: Arbitrary code execution via crafted TIF file parsing (CVE-2026-18304)
* gimp: GIMP: Remote code execution via PSD file parsing integer overflow (CVE-2026-18301)
* gimp: GIMP: Remote Code Execution via TIF file parsing integer overflow (CVE-2026-18305)
* gimp: GIMP: Remote code execution via TIF file parsing vulnerability (CVE-2026-18303)
* gimp: GIMP: Remote Code Execution via SGI File Parsing Integer Overflow (CVE-2026-18306)
* gimp: GIMP: Remote code execution via TIF file parsing heap-based buffer overflow (CVE-2026-18307)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.