GIMP prior to version 3.0.0 is vulnerable to two buffer over-reads and one heap-based buffer overflow in its TGA parser. A malicious TGA file may attempt to abuse these vulnerabilities to achieve code execution.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:9162 https://access.redhat.com/errata/RHSA-2025:9162
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:9165 https://access.redhat.com/errata/RHSA-2025:9165