[CLSA-2026:1787683852] gimp: Fix of CVE-2026-59088
Type:
security
Severity:
Moderate
Release date:
2026-08-25 18:51:02 UTC
Description:
- CVE-2026-59088: prevent signed integer overflow of the width-by-height product in the FLI plug-in by widening the multiplication to gsize/gint64 in the frame buffer allocations, memset and memcpy calls, and by switching the allocations to g_try_malloc with a failure check
CVEs fixed:
Updated packages:
  • gimp-2.99.8-4.el9.2.tuxcare.els17.x86_64.rpm
    sha:bc670083b62611632ccb25e27d6f77e6d47aff73c27c2059c4582ed2d6a03c73
  • gimp-devel-2.99.8-4.el9.2.tuxcare.els17.x86_64.rpm
    sha:f9b6680750e3aeb4c742c6e5f98b0a1edb014f6afb1ed15e44783eb5ec85397c
  • gimp-devel-tools-2.99.8-4.el9.2.tuxcare.els17.x86_64.rpm
    sha:657425cb4c30953e8edb500ef8a2940f5acbfcf53f89612bb8643ab9f000cd46
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els17.i686.rpm
    sha:576a326d5e90b458b345410c925deb835e2c377c9f41c2c15a0f378299205821
  • gimp-libs-2.99.8-4.el9.2.tuxcare.els17.x86_64.rpm
    sha:6049e0b76874480acd0b69255603da3f4e74d74a474311bb26a6ba31c38540d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.