[CLSA-2026:1787333229] gimp: Fix of CVE-2026-59090
Type:
security
Severity:
Critical
Release date:
2026-08-21 17:27:18 UTC
Description:
- CVE-2026-59090: prevent unsigned integer underflow of block_rem in the PSD loader by bounds-checking the blending ranges length, the layer name length and the layer resource header size before subtracting them
CVEs fixed:
Updated packages:
  • gimp-2.99.8-4.el9_6.2.tuxcare.els16.x86_64.rpm
    sha:947fe9ea88b2a325d2013267dcf2a685e98af6ea16d72202f8eca22494dd7e36
  • gimp-devel-2.99.8-4.el9_6.2.tuxcare.els16.x86_64.rpm
    sha:8fe28ad29d96810bee979f61faa44132fef1a2a456d2b485de1bee4e14722370
  • gimp-devel-tools-2.99.8-4.el9_6.2.tuxcare.els16.x86_64.rpm
    sha:a0f3acebd26afe11bae8af4716cfe66d15ec1d037e5aa1eba2863ab6546f8ed3
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els16.i686.rpm
    sha:2bec0f4dcc6f64f544ca4d1aad97a5e94f267529b209166b221c730f9e5db12e
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els16.x86_64.rpm
    sha:f70119aeb00871752e81f4a8f3b4dd6015fff4a8214d8e31b2cbba3935df512b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.