openSUSE-SU-2026:21521-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21521-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21521-1
Upstream
CVE (3)
Related
Published
2026-08-03T10:59:51Z
Modified
2026-08-05T18:23:43Z
Summary
Security update for gimp
Details

This update for gimp fixes the following issues:

Changes in gimp:

  • CVE-2026-66757: signed integer overflow in file-sgi causes the plugin to crash when RLE-compressed SGI images are processed (bsc#1273151)
  • CVE-2026-66758: integer overflow in file-fits plugin causes a heap-based buffer overflow when crafted FITS images are processed (bsc#1273152)
  • CVE-2026-66759: out-of-bounds read in file-icns plugin causes information disclosure or crash when crafted ICNS images are processed (bsc#1273153)
References

Affected packages

openSUSE:Leap 16.0 / gimp

Package

Name
gimp
Purl
pkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.8-bp160.6.1

Ecosystem specific

{
    "binaries": [
        {
            "gimp": "3.0.8-bp160.6.1",
            "gimp-devel": "3.0.8-bp160.6.1",
            "gimp-extension-goat-excercises": "3.0.8-bp160.6.1",
            "gimp-lang": "3.0.8-bp160.6.1",
            "gimp-plugin-aa": "3.0.8-bp160.6.1",
            "gimp-plugin-python3": "3.0.8-bp160.6.1",
            "gimp-vala": "3.0.8-bp160.6.1",
            "libgimp-3_0-0": "3.0.8-bp160.6.1",
            "libgimpui-3_0-0": "3.0.8-bp160.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21521-1.json"