CVE-2026-4887

high
Published 2026-05-12 ยท Modified 2026-05-14
CVSS v3
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.1

Description

Important: gimp security update

Predictions

Exploit likelihood
70%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image Red Hat statement Moderate: This flaw in GIMP's PCX file loader is due to a heap buffer over-read. Exploitation requires user interaction, specifically opening a specially crafted PCX image file. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted PCX files.โ€ฆ

Description

gimp: GIMP:Memory disclosure and denial of service via specially crafted PCX image

Red Hat statement

Moderate: This flaw in GIMP's PCX file loader is due to a heap buffer over-read. Exploitation requires user interaction, specifically opening a specially crafted PCX image file. Red Hat Enterprise Linux systems are affected if GIMP is installed and used to open untrusted PCX files.

CVSS v3: 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8gimp:2.8-8100020260512115927.4c9c024fRHSA-2026:175332026-05-14T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportgimp:2.8-8040020260520140422.70584597RHSA-2026:205522026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Ongimp:2.8-8040020260520140422.70584597RHSA-2026:205522026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportgimp:2.8-8060020260520140100.6af1eaf0RHSA-2026:205532026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicegimp:2.8-8060020260520140100.6af1eaf0RHSA-2026:205532026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsgimp:2.8-8060020260520140100.6af1eaf0RHSA-2026:205532026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicegimp:2.8-8080020260520102644.0621e4eeRHSA-2026:205542026-05-26T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsgimp:2.8-8080020260520102644.0621e4eeRHSA-2026:205542026-05-26T00:00:00Z
Red Hat Enterprise Linux 9gimp-2:3.0.4-1.el9_7.5RHSA-2026:164842026-05-12T00:00:00Z
Red Hat Enterprise Linux 9gimp-2:3.0.4-4.el9_8.4RHSA-2026:193622026-05-19T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsgimp-2:2.99.8-3.el9_0.6RHSA-2026:206912026-05-26T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6gimpOut of support scope
Red Hat Enterprise Linux 7gimpAffected

Apply commands

bash fix
Apply RHSA-2026:17533 for Red Hat Enterprise Linux 8
yum update -y gimp:2
# or:
dnf upgrade -y gimp:2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 7Affected

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed3.2.0-1
debian debiansidfixed3.2.0-1
debian debiantrixieaffected
suse slesaffected
redhat rhel6.0not-affected
redhat rhel7.0not-affected
redhat rhel8.0not-affected
redhat rhel9.0not-affected
almalinux almalinux9fixedgimp-libs-3.0.4-1.el9_7.5.aarch64.rpm

Application impact

VendorProductVersionsFixed
gimpgimp{"endExcluding":"3.2.0"}3.2.0
gimpgimp3.2.0

References

CWEs

CWE-193

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.