Back to Security Advisories
High 2026-08-06

Gimp Security Update — AlmaLinux 9 (ALSA-2026:50817)

AlmaLinux 9

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: GIMP APNG loade…

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

* gimp: GIMP APNG loade…

Type:
security

Severity:
important

Release date:
2026-08-06

Description:
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

* gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c) (CVE-2026-42169)
* gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images (CVE-2026-66758)
* gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images (CVE-2026-66759)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 gimp-libs-3.0.4-4.el9_8.9.aarch64.rpm 08cd5c9abfdc29426f2fae420c09bb3398a3195fc1f34d1e832aff387cc40c3e
aarch64 gimp-3.0.4-4.el9_8.9.aarch64.rpm 9f6cbf7cdc0c6d2c683d07ef7fb970b0b4361792e285abc5313d681106267918
i686 gimp-libs-3.0.4-4.el9_8.9.i686.rpm 230c1bfa61326ddf228c181af29bdd6a0f369ca7d02f4f4025b7abdd45800c4c
ppc64le gimp-libs-3.0.4-4.el9_8.9.ppc64le.rpm 7ccdf72234acfb5e0f281d9f3f4698b5841a03593751e08266ad92991f2d0742
ppc64le gimp-3.0.4-4.el9_8.9.ppc64le.rpm b97c4484db3b13f441001d6f03607feefe2e443948d5e028942bd7b87cebb4e4
x86_64 gimp-3.0.4-4.el9_8.9.x86_64.rpm 8533d646b536c6e18fbfd56a816bcc8f56a33a1af32ef24653c185861acd07bb
x86_64 gimp-libs-3.0.4-4.el9_8.9.x86_64.rpm c0cc43b0dfe4792e0d96063816e0d24c103c43ced0b22053ee13486e25bbc766

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System