[CLSA-2026:1787330254] gimp: Fix of CVE-2026-59090
Type:
security
Severity:
Critical
Release date:
2026-08-21 16:37:44 UTC
Description:
- CVE-2026-59090: prevent unsigned integer underflow of block_rem in the PSD loader by bounds-checking the blending ranges length, the layer name length and the layer resource header size before subtracting them
CVEs fixed:
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els16.x86_64.rpm
    sha:4114fb406dc15aa0d5961961cb221aac5ba0c1d1b883b2208b449a4e0e83cb3b
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els16.x86_64.rpm
    sha:6a730e785727fbf833b1907d1f1c9657d6ead80c9199e9ad235a5c50f5b74340
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els16.x86_64.rpm
    sha:289fb97151f6e3eb7fa34dee4bcc91d4efd7fd2b68ef0d2656d18462dd0b237c
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els16.i686.rpm
    sha:4fcea115e17a281920bb30fc1e7065b625de578dda4af9eb804985bb6fdaad60
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els16.x86_64.rpm
    sha:af0ad13247e7c269625c7acc6b3a4e8713f67730d5fcf74484613f949d9da0e4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.