Описание
Security update for gimp
This update for gimp fixes the following issue:
- CVE-2026-4887: Memory disclosure and denial of service via specially crafted PCX image (bsc#1260837).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
gimp-2.10.30-150400.3.53.1
gimp-devel-2.10.30-150400.3.53.1
gimp-lang-2.10.30-150400.3.53.1
gimp-plugin-aa-2.10.30-150400.3.53.1
libgimp-2_0-0-2.10.30-150400.3.53.1
libgimpui-2_0-0-2.10.30-150400.3.53.1
SUSE Linux Enterprise Workstation Extension 15 SP7
gimp-2.10.30-150400.3.53.1
gimp-devel-2.10.30-150400.3.53.1
gimp-lang-2.10.30-150400.3.53.1
libgimp-2_0-0-2.10.30-150400.3.53.1
libgimpui-2_0-0-2.10.30-150400.3.53.1
Ссылки
- Link for SUSE-SU-2026:2756-1
- E-Mail link for SUSE-SU-2026:2756-1
- SUSE Security Ratings
- SUSE Bug 1260837
- SUSE CVE CVE-2026-4887 page
Описание
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A remote attacker could exploit this by convincing a user to open a specially crafted PCX image. Successful exploitation could lead to out-of-bounds memory disclosure and a possible application crash, resulting in a Denial of Service (DoS).
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:gimp-2.10.30-150400.3.53.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:gimp-devel-2.10.30-150400.3.53.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:gimp-lang-2.10.30-150400.3.53.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:gimp-plugin-aa-2.10.30-150400.3.53.1
Ссылки
- CVE-2026-4887
- SUSE Bug 1260837