Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22445 - Security Advisory
Issued:
2025-12-01
Updated:
2025-12-01

RHSA-2025:22445 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.6 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10922)
  • gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10934)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2407188 - CVE-2025-10922 gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • BZ - 2407233 - CVE-2025-10934 gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVEs

  • CVE-2025-10922
  • CVE-2025-10934

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
x86_64
gimp-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4fd55a3fa0572dc82027e7567d218d930b5ed3a4e9fceae5a4a82c08705d8549
gimp-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 91758bc53c82949a5ea0e598aca1c70c218c211e234327e7bef3ffda5e884067
gimp-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: b952a95815d7b07ffec23a5e1c5f87ce5ede70b32165cb3859e703a8b2443de9
gimp-debugsource-2.99.8-4.el9_6.3.i686.rpm SHA-256: f8b049d5f76d8df5e15da55c0a1df11a639e99fbd16d3e60f55b4b8f218b098d
gimp-debugsource-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4ca2a280e15f5f37a99695bd219ba1f8ba6d59a721d977cb9716e17f5c991e19
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 85a8875c246817cdccd3c84b9203ff56fa5b80cb7e9f8796ebc0ef22b846a3ec
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 34e69de834fcbbb7485d57610edec197b7454605285bcb5e5c76b42d2a9c59d5
gimp-libs-2.99.8-4.el9_6.3.i686.rpm SHA-256: c2c1f2e320fd5f0f04b5b1ee91ee78d1218d15a64c7664e71da94ce6de20ff77
gimp-libs-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 7ca935f886a5179338d420513be4e52a4b0befc13153a4a33097ee3088a4613b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 668950aacc687652829427adead5c1b5433a6257ec886bef1b0c00e103a8296b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 8999019b6a74330de6216d3daa36ea04335513b3a413a49401d99a4380ca1082

Red Hat Enterprise Linux Server - AUS 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
x86_64
gimp-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4fd55a3fa0572dc82027e7567d218d930b5ed3a4e9fceae5a4a82c08705d8549
gimp-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 91758bc53c82949a5ea0e598aca1c70c218c211e234327e7bef3ffda5e884067
gimp-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: b952a95815d7b07ffec23a5e1c5f87ce5ede70b32165cb3859e703a8b2443de9
gimp-debugsource-2.99.8-4.el9_6.3.i686.rpm SHA-256: f8b049d5f76d8df5e15da55c0a1df11a639e99fbd16d3e60f55b4b8f218b098d
gimp-debugsource-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4ca2a280e15f5f37a99695bd219ba1f8ba6d59a721d977cb9716e17f5c991e19
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 85a8875c246817cdccd3c84b9203ff56fa5b80cb7e9f8796ebc0ef22b846a3ec
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 34e69de834fcbbb7485d57610edec197b7454605285bcb5e5c76b42d2a9c59d5
gimp-libs-2.99.8-4.el9_6.3.i686.rpm SHA-256: c2c1f2e320fd5f0f04b5b1ee91ee78d1218d15a64c7664e71da94ce6de20ff77
gimp-libs-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 7ca935f886a5179338d420513be4e52a4b0befc13153a4a33097ee3088a4613b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 668950aacc687652829427adead5c1b5433a6257ec886bef1b0c00e103a8296b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 8999019b6a74330de6216d3daa36ea04335513b3a413a49401d99a4380ca1082

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
s390x
gimp-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 4b35477f20f7c5451af7891e04b7c69b22897dfde11be3d65c68bbee35f198a8
gimp-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: dc8862ce1599a93676821d07d745f572ebc4833cc5454c162cc49489268d059f
gimp-debugsource-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 6ec16bc20afafa59ea8bb2d4cb970ccd76bf8f814efcf515c6d989e37d943b3f
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: c9c7c6e7948666f388a85487d3626a9a219fe017f258271295afba10447f8fd5
gimp-libs-2.99.8-4.el9_6.3.s390x.rpm SHA-256: db96ae546890ad53489bdc45afc32ed4ba3f38fecaac354ff1ac8695faf0d612
gimp-libs-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 853a8ddb481800f308897842f69c28e153649f1d9785fa7e5d5df9ee76ae5c3e

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
ppc64le
gimp-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 8bba4ece3e13a1195d970ab884d7c1059cfc5fc5a00cc54b6bd9624b92e758a9
gimp-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: c14160c96c41384ba9f9484013b9fe7362a23d5f328840502a9aeff2a4be5365
gimp-debugsource-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 6d56d80e2f324c3bf88ab846cdc87acd718e375778fc2085ca86fb81c03c41ac
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: f97d084c45506097b4f232145fc4b78a17947735c2edc2cdedf8dbfdc8e6b819
gimp-libs-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: f1126fb8f796c4864d51dc44ccf93319dd34a4cac52248144e4d4a65a8b5b27f
gimp-libs-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 39577e36114e96a1da5a4d55ba9306499e361f3963e2fb34bf9519dc82aa3ba5

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
aarch64
gimp-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: b4101aa219f611837683e0435ce113d6e98ef124ac4f20f63b88f5772c4c0f6f
gimp-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: f09242dcbb5de4dc6470ed88bf6f3c5575495447cce7e671493763245c7cd9fb
gimp-debugsource-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: c079a319371e151c71e2cfc23785f4a35a83802803cf258ee9454d6f576c2877
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 6f08ae57d422024fb8d49a767b961f95972dc8eb0b6ad06a51d8949370cf31c5
gimp-libs-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 28c0761d423bcce6c37da200adea964fbb2bca5bc7ab23da8eb2ba24f6b04320
gimp-libs-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 367e9214cec5f4498ade4aefbdca67e9335249bef65c08d3550b767870971b56

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
ppc64le
gimp-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 8bba4ece3e13a1195d970ab884d7c1059cfc5fc5a00cc54b6bd9624b92e758a9
gimp-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: c14160c96c41384ba9f9484013b9fe7362a23d5f328840502a9aeff2a4be5365
gimp-debugsource-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 6d56d80e2f324c3bf88ab846cdc87acd718e375778fc2085ca86fb81c03c41ac
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: f97d084c45506097b4f232145fc4b78a17947735c2edc2cdedf8dbfdc8e6b819
gimp-libs-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: f1126fb8f796c4864d51dc44ccf93319dd34a4cac52248144e4d4a65a8b5b27f
gimp-libs-debuginfo-2.99.8-4.el9_6.3.ppc64le.rpm SHA-256: 39577e36114e96a1da5a4d55ba9306499e361f3963e2fb34bf9519dc82aa3ba5

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
x86_64
gimp-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4fd55a3fa0572dc82027e7567d218d930b5ed3a4e9fceae5a4a82c08705d8549
gimp-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 91758bc53c82949a5ea0e598aca1c70c218c211e234327e7bef3ffda5e884067
gimp-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: b952a95815d7b07ffec23a5e1c5f87ce5ede70b32165cb3859e703a8b2443de9
gimp-debugsource-2.99.8-4.el9_6.3.i686.rpm SHA-256: f8b049d5f76d8df5e15da55c0a1df11a639e99fbd16d3e60f55b4b8f218b098d
gimp-debugsource-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 4ca2a280e15f5f37a99695bd219ba1f8ba6d59a721d977cb9716e17f5c991e19
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 85a8875c246817cdccd3c84b9203ff56fa5b80cb7e9f8796ebc0ef22b846a3ec
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 34e69de834fcbbb7485d57610edec197b7454605285bcb5e5c76b42d2a9c59d5
gimp-libs-2.99.8-4.el9_6.3.i686.rpm SHA-256: c2c1f2e320fd5f0f04b5b1ee91ee78d1218d15a64c7664e71da94ce6de20ff77
gimp-libs-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 7ca935f886a5179338d420513be4e52a4b0befc13153a4a33097ee3088a4613b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.i686.rpm SHA-256: 668950aacc687652829427adead5c1b5433a6257ec886bef1b0c00e103a8296b
gimp-libs-debuginfo-2.99.8-4.el9_6.3.x86_64.rpm SHA-256: 8999019b6a74330de6216d3daa36ea04335513b3a413a49401d99a4380ca1082

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
aarch64
gimp-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: b4101aa219f611837683e0435ce113d6e98ef124ac4f20f63b88f5772c4c0f6f
gimp-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: f09242dcbb5de4dc6470ed88bf6f3c5575495447cce7e671493763245c7cd9fb
gimp-debugsource-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: c079a319371e151c71e2cfc23785f4a35a83802803cf258ee9454d6f576c2877
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 6f08ae57d422024fb8d49a767b961f95972dc8eb0b6ad06a51d8949370cf31c5
gimp-libs-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 28c0761d423bcce6c37da200adea964fbb2bca5bc7ab23da8eb2ba24f6b04320
gimp-libs-debuginfo-2.99.8-4.el9_6.3.aarch64.rpm SHA-256: 367e9214cec5f4498ade4aefbdca67e9335249bef65c08d3550b767870971b56

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6

SRPM
gimp-2.99.8-4.el9_6.3.src.rpm SHA-256: 9449ff56e248e68a0978d3a71d1d63f399602f09f558711e57a9b9968c87e4df
s390x
gimp-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 4b35477f20f7c5451af7891e04b7c69b22897dfde11be3d65c68bbee35f198a8
gimp-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: dc8862ce1599a93676821d07d745f572ebc4833cc5454c162cc49489268d059f
gimp-debugsource-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 6ec16bc20afafa59ea8bb2d4cb970ccd76bf8f814efcf515c6d989e37d943b3f
gimp-devel-tools-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: c9c7c6e7948666f388a85487d3626a9a219fe017f258271295afba10447f8fd5
gimp-libs-2.99.8-4.el9_6.3.s390x.rpm SHA-256: db96ae546890ad53489bdc45afc32ed4ba3f38fecaac354ff1ac8695faf0d612
gimp-libs-debuginfo-2.99.8-4.el9_6.3.s390x.rpm SHA-256: 853a8ddb481800f308897842f69c28e153649f1d9785fa7e5d5df9ee76ae5c3e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility