Fedora Account System
Red Hat Associate
Red Hat Customer
A source-level audit of GIMP's file format plugins identified 2 vulnerabilities in default-install plugins (file-psd, file-paa). Both are triggerable by opening a crafted image file — no user interaction beyond "File > Open" is required. Each finding has been independently reproduced with a standalone PoC and confirmed via AddressSanitizer or arithmetic verification in a Docker environment (Fedora 41, gcc, zlib-devel). https://gitlab.gnome.org/GNOME/gimp/-/work_items/16509
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61587 https://access.redhat.com/errata/RHSA-2026:61587
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:73768 https://access.redhat.com/errata/RHSA-2026:73768