[CLSA-2026:1787682600] gimp: Fix of CVE-2026-59088
Type:
security
Severity:
Moderate
Release date:
2026-08-25 18:30:10 UTC
Description:
- CVE-2026-59088: prevent signed integer overflow of the width-by-height product in the FLI plug-in by widening the multiplication to gsize/gint64 in the frame buffer allocations, memset and memcpy calls, and by switching the allocations to g_try_malloc with a failure check
CVEs fixed:
Updated packages:
  • gimp-2.99.8-4.el9_6.2.tuxcare.els17.x86_64.rpm
    sha:5aadf6f97890d3340f038c2b421bb2a642036f13c00f4236fdd19b6e05dd70d0
  • gimp-devel-2.99.8-4.el9_6.2.tuxcare.els17.x86_64.rpm
    sha:a79a7fc0e02345087e1b157da3b7d7233c02bfc74449e7fb2b7691e736e903f2
  • gimp-devel-tools-2.99.8-4.el9_6.2.tuxcare.els17.x86_64.rpm
    sha:b37cd3a4113a2f64349f012ee52b3c90b39feb9a2c626862a52928a1a996a712
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els17.i686.rpm
    sha:2031b52b934c85fd5fd7b230c7b7389ac505298f4f78b313ef34403a92812738
  • gimp-libs-2.99.8-4.el9_6.2.tuxcare.els17.x86_64.rpm
    sha:386c3412ab4645dfcb7f0e3f59b43ea49d47e1d05226b6525f574545e93598fa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.