GIMP prior to version 3.0.0 is vulnerable to two buffer over-reads and one heap-based buffer overflow in its TGA parser. A malicious TGA file may attempt to abuse these vulnerabilities to achieve code execution.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9162 https://access.redhat.com/errata/RHSA-2025:9162
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9165 https://access.redhat.com/errata/RHSA-2025:9165
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:9315 https://access.redhat.com/errata/RHSA-2025:9315
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2025:9310 https://access.redhat.com/errata/RHSA-2025:9310
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:9314 https://access.redhat.com/errata/RHSA-2025:9314
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2025:9308 https://access.redhat.com/errata/RHSA-2025:9308
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:9316 https://access.redhat.com/errata/RHSA-2025:9316
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:9309 https://access.redhat.com/errata/RHSA-2025:9309
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2025:9501 https://access.redhat.com/errata/RHSA-2025:9501
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:9569 https://access.redhat.com/errata/RHSA-2025:9569