SUSE-SU-2026:4409-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264409-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4409-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4409-1
Upstream
CVE (10)
Related
Published
2026-10-01T07:07:35Z
Modified
2026-10-01T17:30:06Z
Summary
Security update for gimp
Details

This update for gimp fixes the following issues:

  • CVE-2026-18301: Vulnerability Report at read_channel_data (bsc#1276230).
  • CVE-2026-18302: TIF File Parsing Heap-based Buffer Overflow (bsc#1276231).
  • CVE-2026-18303: TIF File Parsing Stack-based Buffer Overflow (bsc#1276232).
  • CVE-2026-18304: TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276233).
  • CVE-2026-18305: TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276234).
  • CVE-2026-18306: SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276235).
  • CVE-2026-18307: File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276236).
  • CVE-2026-90947: out-of-bounds write in the lighting effects plugin when processing a crafted preset file due to improper validation of the number of light sources (bsc#1280511).
  • CVE-2026-90948: heap buffer overflow in the ICO loader when processing ICO files with embedded PNG images due to an integer overflow during calculation of buffer sizes (bsc#1280512).
  • CVE-2026-92248: integer overflow when generating a thumbnail preview for a PSD file can lead to a heap buffer overflow (bsc#1280739).
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7
gimp

Package

Name
gimp
Purl
pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.10.30-150400.3.79.1

Ecosystem specific

{
    "binaries":  [
        {
            "gimp":  "2.10.30-150400.3.79.1",
            "gimp-devel":  "2.10.30-150400.3.79.1",
            "gimp-lang":  "2.10.30-150400.3.79.1",
            "gimp-plugin-aa":  "2.10.30-150400.3.79.1",
            "libgimp-2_0-0":  "2.10.30-150400.3.79.1",
            "libgimpui-2_0-0":  "2.10.30-150400.3.79.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4409-1.json"
SUSE:Linux Enterprise Workstation Extension 15 SP7
gimp

Package

Name
gimp
Purl
pkg:rpm/suse/gimp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.10.30-150400.3.79.1

Ecosystem specific

{
    "binaries":  [
        {
            "gimp":  "2.10.30-150400.3.79.1",
            "gimp-devel":  "2.10.30-150400.3.79.1",
            "gimp-lang":  "2.10.30-150400.3.79.1",
            "libgimp-2_0-0":  "2.10.30-150400.3.79.1",
            "libgimpui-2_0-0":  "2.10.30-150400.3.79.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4409-1.json"