Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22496 - Security Advisory
Issued:
2025-12-01
Updated:
2025-12-01

RHSA-2025:22496 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10922)
  • gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10934)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2407188 - CVE-2025-10922 gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • BZ - 2407233 - CVE-2025-10934 gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVEs

  • CVE-2025-10922
  • CVE-2025-10934

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
x86_64
gimp-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 6e27a52cc02525a64f5a0de2e0008581a7c5a2d77cabbdbb7132b20875cb994a
gimp-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: c4e4684600425593fce2ab03cb146df455ca842b71a2ddecd17cb2e162bbf44f
gimp-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d09ab15a7feba547b92b1d6a62b9725fe4b9d34df6f5909c51f2c0782f2b8fa3
gimp-debugsource-2.99.8-4.el9_4.2.i686.rpm SHA-256: b8578381ceb7b424b3031afc7e334f64ea7138a733e04d03469ff52dd02d6e24
gimp-debugsource-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d28cd7519a2a81ed920c26d8bdbef7387b5c06b768a95984eef07cec374ab321
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 37286c30704b79c2074a57fb63fbc375fd6980a9a6b521ec2cf131d5bbb3f948
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 9ae02ab2ad0e909ffb7ac3151e5888bb3ceb7278a1d58dc79a5d87562650e89b
gimp-libs-2.99.8-4.el9_4.2.i686.rpm SHA-256: 4810efd675c3898b89a92f09837a13bf960c8df37622dff0ab627a698c14f76f
gimp-libs-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 7ddc1824a6d1e5670547cdf46ec12edf4515a62eb4455329aae1ea01a63c14f6
gimp-libs-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 756c4f01c1391360b89f3296fd5401e320ffb9ecc8b12770609c264c282f8c2d
gimp-libs-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 8e560f201861ea0c38539387171077531ac7575060020261ac724407e5c403c7

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
x86_64
gimp-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 6e27a52cc02525a64f5a0de2e0008581a7c5a2d77cabbdbb7132b20875cb994a
gimp-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: c4e4684600425593fce2ab03cb146df455ca842b71a2ddecd17cb2e162bbf44f
gimp-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d09ab15a7feba547b92b1d6a62b9725fe4b9d34df6f5909c51f2c0782f2b8fa3
gimp-debugsource-2.99.8-4.el9_4.2.i686.rpm SHA-256: b8578381ceb7b424b3031afc7e334f64ea7138a733e04d03469ff52dd02d6e24
gimp-debugsource-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d28cd7519a2a81ed920c26d8bdbef7387b5c06b768a95984eef07cec374ab321
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 37286c30704b79c2074a57fb63fbc375fd6980a9a6b521ec2cf131d5bbb3f948
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 9ae02ab2ad0e909ffb7ac3151e5888bb3ceb7278a1d58dc79a5d87562650e89b
gimp-libs-2.99.8-4.el9_4.2.i686.rpm SHA-256: 4810efd675c3898b89a92f09837a13bf960c8df37622dff0ab627a698c14f76f
gimp-libs-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 7ddc1824a6d1e5670547cdf46ec12edf4515a62eb4455329aae1ea01a63c14f6
gimp-libs-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 756c4f01c1391360b89f3296fd5401e320ffb9ecc8b12770609c264c282f8c2d
gimp-libs-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 8e560f201861ea0c38539387171077531ac7575060020261ac724407e5c403c7

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
s390x
gimp-2.99.8-4.el9_4.2.s390x.rpm SHA-256: debf1f218840d1003b176571547b12877f5bb96ca88c38a30940bf3be407ba6a
gimp-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: ecc9223a62f483082685009570be0444a83ab2a307c92f00c7e9e887f2ae22c0
gimp-debugsource-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 8439a73e287806804dde2110889837f106e573decc8e28bbf9d3cbef4a30fa6f
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 90c2d3d291f9164a582e72dde0db5b7224fbccf49d8da66ed9ece0c4e342f6a6
gimp-libs-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 2b3e1c500e42639b5ccc472f11700b0f6877ea87032a85863afd0e7542d557b2
gimp-libs-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 0d5f3c40de253fe22b62f561e851ffadc1b72ae75bf4ca8d238a6b860ae17db9

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
ppc64le
gimp-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: 514295a41118c6280b72bb130755c43a12b01f860e7a139acdc0e95349678810
gimp-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: a7a9989b403bd82b411266fa3542fe39daecb2fc7dc1e9a84a0a99f9d123f81d
gimp-debugsource-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: e8c5a9e8dc3a317bbe93b92139f78690d0aad6c1486d03cd5c66f9ee05016fb9
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: d7f77c16aa65430ba90163988a9a51da7609a3dce6411dc9e5ae15671b36ef1f
gimp-libs-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: c61db711fd6e7e1662b6f407bd2a7dc70a14161bc2826f070c3886e1ecbed10c
gimp-libs-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: e509fac37c05813d0584b85bed2876062eb2fd14a8208a2bf9c8e547a3b67206

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
aarch64
gimp-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: ce03b730b663fabe6e36d24d92cea17f76accf18db64379547b91fef482d18ee
gimp-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 6d2f6abf0f3f1eb4805c926cb3b2d9718ecd58292b8b80829302ff8cf57d3e80
gimp-debugsource-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: f311b0ab6f74a00804cb48c1533f231427151e2a7832489f435b96426fe41f09
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: d952fa4b1cc8c1c73ae9ed161a968e749a17e51237bb17926ef359a3a655fb17
gimp-libs-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 995cb9cf520b4743324a4f0decbbdbb1e368f4505f63f0e1d29ef353681866c7
gimp-libs-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 843348c3deff1361a3b66208273e0f45e8c30ba6016342a721647a0b280a9c96

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
ppc64le
gimp-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: 514295a41118c6280b72bb130755c43a12b01f860e7a139acdc0e95349678810
gimp-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: a7a9989b403bd82b411266fa3542fe39daecb2fc7dc1e9a84a0a99f9d123f81d
gimp-debugsource-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: e8c5a9e8dc3a317bbe93b92139f78690d0aad6c1486d03cd5c66f9ee05016fb9
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: d7f77c16aa65430ba90163988a9a51da7609a3dce6411dc9e5ae15671b36ef1f
gimp-libs-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: c61db711fd6e7e1662b6f407bd2a7dc70a14161bc2826f070c3886e1ecbed10c
gimp-libs-debuginfo-2.99.8-4.el9_4.2.ppc64le.rpm SHA-256: e509fac37c05813d0584b85bed2876062eb2fd14a8208a2bf9c8e547a3b67206

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
x86_64
gimp-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 6e27a52cc02525a64f5a0de2e0008581a7c5a2d77cabbdbb7132b20875cb994a
gimp-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: c4e4684600425593fce2ab03cb146df455ca842b71a2ddecd17cb2e162bbf44f
gimp-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d09ab15a7feba547b92b1d6a62b9725fe4b9d34df6f5909c51f2c0782f2b8fa3
gimp-debugsource-2.99.8-4.el9_4.2.i686.rpm SHA-256: b8578381ceb7b424b3031afc7e334f64ea7138a733e04d03469ff52dd02d6e24
gimp-debugsource-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: d28cd7519a2a81ed920c26d8bdbef7387b5c06b768a95984eef07cec374ab321
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 37286c30704b79c2074a57fb63fbc375fd6980a9a6b521ec2cf131d5bbb3f948
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 9ae02ab2ad0e909ffb7ac3151e5888bb3ceb7278a1d58dc79a5d87562650e89b
gimp-libs-2.99.8-4.el9_4.2.i686.rpm SHA-256: 4810efd675c3898b89a92f09837a13bf960c8df37622dff0ab627a698c14f76f
gimp-libs-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 7ddc1824a6d1e5670547cdf46ec12edf4515a62eb4455329aae1ea01a63c14f6
gimp-libs-debuginfo-2.99.8-4.el9_4.2.i686.rpm SHA-256: 756c4f01c1391360b89f3296fd5401e320ffb9ecc8b12770609c264c282f8c2d
gimp-libs-debuginfo-2.99.8-4.el9_4.2.x86_64.rpm SHA-256: 8e560f201861ea0c38539387171077531ac7575060020261ac724407e5c403c7

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
aarch64
gimp-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: ce03b730b663fabe6e36d24d92cea17f76accf18db64379547b91fef482d18ee
gimp-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 6d2f6abf0f3f1eb4805c926cb3b2d9718ecd58292b8b80829302ff8cf57d3e80
gimp-debugsource-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: f311b0ab6f74a00804cb48c1533f231427151e2a7832489f435b96426fe41f09
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: d952fa4b1cc8c1c73ae9ed161a968e749a17e51237bb17926ef359a3a655fb17
gimp-libs-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 995cb9cf520b4743324a4f0decbbdbb1e368f4505f63f0e1d29ef353681866c7
gimp-libs-debuginfo-2.99.8-4.el9_4.2.aarch64.rpm SHA-256: 843348c3deff1361a3b66208273e0f45e8c30ba6016342a721647a0b280a9c96

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
gimp-2.99.8-4.el9_4.2.src.rpm SHA-256: e606de18e6075a01a842722454714f78fd6c4510f29561051549ff3e46d45d67
s390x
gimp-2.99.8-4.el9_4.2.s390x.rpm SHA-256: debf1f218840d1003b176571547b12877f5bb96ca88c38a30940bf3be407ba6a
gimp-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: ecc9223a62f483082685009570be0444a83ab2a307c92f00c7e9e887f2ae22c0
gimp-debugsource-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 8439a73e287806804dde2110889837f106e573decc8e28bbf9d3cbef4a30fa6f
gimp-devel-tools-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 90c2d3d291f9164a582e72dde0db5b7224fbccf49d8da66ed9ece0c4e342f6a6
gimp-libs-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 2b3e1c500e42639b5ccc472f11700b0f6877ea87032a85863afd0e7542d557b2
gimp-libs-debuginfo-2.99.8-4.el9_4.2.s390x.rpm SHA-256: 0d5f3c40de253fe22b62f561e851ffadc1b72ae75bf4ca8d238a6b860ae17db9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility