Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21959-1

Опубликовано: 24 сент. 2026
Источник: suse-cvrf

Описание

Security update for gimp

This update for gimp fixes the following issues:

Changes in gimp:

  • CVE-2026-18304: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276233)
  • CVE-2026-18301: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276230)
  • CVE-2026-18307: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276236)
  • CVE-2026-18303: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276232)
  • CVE-2026-18308: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276237)
  • CVE-2026-18306: GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276235)
  • CVE-2026-18305: GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276234)
  • CVE-2026-18302: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276231)
  • CVE-2026-90947: out-of-bounds write in the lighting effects plugin when processing a crafted preset file due to improper validation of the number of light sources (bsc#1280511)
  • CVE-2026-90948: When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size (bsc#1280512)
  • CVE-2026-92248: When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header (bsc#1280739)

Список пакетов

openSUSE Leap 16.0
gimp-3.0.8-bp160.10.1
gimp-devel-3.0.8-bp160.10.1
gimp-extension-goat-excercises-3.0.8-bp160.10.1
gimp-lang-3.0.8-bp160.10.1
gimp-plugin-aa-3.0.8-bp160.10.1
gimp-plugin-python3-3.0.8-bp160.10.1
gimp-vala-3.0.8-bp160.10.1
libgimp-3_0-0-3.0.8-bp160.10.1
libgimpui-3_0-0-3.0.8-bp160.10.1

Описание

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29395.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29398.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29399.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29403.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29406.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SGI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29396.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29404.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29405.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки

Описание

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header. This leads to an undersized heap allocation, resulting in a heap-based buffer overflow when the image data is decoded. This buffer overflow corrupts adjacent heap objects, allowing for a controlled memory write that can result in an application crash or arbitrary code execution.


Затронутые продукты
openSUSE Leap 16.0:gimp-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-devel-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-extension-goat-excercises-3.0.8-bp160.10.1
openSUSE Leap 16.0:gimp-lang-3.0.8-bp160.10.1

Ссылки
Уязвимость openSUSE-SU-2026:21959-1