Bug 2368557 (CVE-2025-48798)
| Summary: | CVE-2025-48798 gimp: Multiple use after free in XCF parser | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2368562 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-05-26 10:52:36 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9162 https://access.redhat.com/errata/RHSA-2025:9162 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9165 https://access.redhat.com/errata/RHSA-2025:9165 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9315 https://access.redhat.com/errata/RHSA-2025:9315 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:9310 https://access.redhat.com/errata/RHSA-2025:9310 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9314 https://access.redhat.com/errata/RHSA-2025:9314 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9308 https://access.redhat.com/errata/RHSA-2025:9308 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9316 https://access.redhat.com/errata/RHSA-2025:9316 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9309 https://access.redhat.com/errata/RHSA-2025:9309 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:9501 https://access.redhat.com/errata/RHSA-2025:9501 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:9569 https://access.redhat.com/errata/RHSA-2025:9569 |