Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29289.
*** Bug 2521117 has been marked as a duplicate of this bug. ***
FEDORA-2026-79b351972c (gegl04-0.4.70-5.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-79b351972c
FEDORA-2026-a05d65f5fa (gegl04-0.4.70-5.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-a05d65f5fa
FEDORA-2026-03ea7c5707 (gegl04-0.4.70-5.fc45) has been submitted as an update to Fedora 45. https://bodhi.fedoraproject.org/updates/FEDORA-2026-03ea7c5707
FEDORA-2026-79b351972c has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-79b351972c` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-79b351972c See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-a05d65f5fa has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a05d65f5fa` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a05d65f5fa See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-03ea7c5707 has been pushed to the Fedora 45 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-03ea7c5707` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-03ea7c5707 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-79b351972c (gegl04-0.4.70-5.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-39b07f6dbb has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-39b07f6dbb` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-39b07f6dbb See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-03ea7c5707 (gegl04-0.4.70-5.fc45) has been pushed to the Fedora 45 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2026-572a0f4178 has been pushed to the Fedora 43 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-572a0f4178` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-572a0f4178 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.