openSUSE-SU-2026:21959-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21959-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21959-1
Upstream
CVE (11)
Related
Published
2026-09-24T14:47:42Z
Modified
2026-09-25T18:24:00Z
Summary
Security update for gimp
Details

This update for gimp fixes the following issues:

Changes in gimp:

  • CVE-2026-18304: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276233)
  • CVE-2026-18301: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276230)
  • CVE-2026-18307: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276236)
  • CVE-2026-18303: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276232)
  • CVE-2026-18308: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276237)
  • CVE-2026-18306: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276235)
  • CVE-2026-18305: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276234)
  • CVE-2026-18302: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276231)
  • CVE-2026-90947: out-of-bounds write in the lighting effects plugin when processing a crafted preset file due to improper validation of the number of light sources (bsc#1280511)
  • CVE-2026-90948: When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size (bsc#1280512)
  • CVE-2026-92248: When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header (bsc#1280739)
References

Affected packages

openSUSE:Leap 16.0 / gimp

Package

Name
gimp
Purl
pkg:rpm/opensuse/gimp&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.8-bp160.10.1

Ecosystem specific

{
    "binaries": [
        {
            "gimp": "3.0.8-bp160.10.1",
            "gimp-devel": "3.0.8-bp160.10.1",
            "gimp-extension-goat-excercises": "3.0.8-bp160.10.1",
            "gimp-lang": "3.0.8-bp160.10.1",
            "gimp-plugin-aa": "3.0.8-bp160.10.1",
            "gimp-plugin-python3": "3.0.8-bp160.10.1",
            "gimp-vala": "3.0.8-bp160.10.1",
            "libgimp-3_0-0": "3.0.8-bp160.10.1",
            "libgimpui-3_0-0": "3.0.8-bp160.10.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21959-1.json"