Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22497 - Security Advisory
Issued:
2025-12-01
Updated:
2025-12-01

RHSA-2025:22497 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10922)
  • gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10934)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2407188 - CVE-2025-10922 gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • BZ - 2407233 - CVE-2025-10934 gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVEs

  • CVE-2025-10922
  • CVE-2025-10934

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.2.src.rpm SHA-256: cb5b89fd7b2f3bea3b87951375247f42a648e841f4ca4401ca10e06597d3f11a
ppc64le
gimp-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: ec5d0b75557aecd32376a40686ea9079d881df9955d1c1db838001485cc48736
gimp-debuginfo-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: b08ae6f9b39f9f4642eff07e97a70cc99f1dd32dc45ce4b955ca473f89c107a6
gimp-debugsource-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: 7157778b6ecc44ff2225fa5baf98cdf2626ff0e793dff55a425bde80d4c05f26
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: b8574368d581fc5e87634066804076f08b0ab7af15e7e560de89f4d215844a54
gimp-libs-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: c41b5d0be837ab58df34b0066f42d126aef7b5beead2da5994353bc0229f9855
gimp-libs-debuginfo-2.99.8-3.el9_0.2.ppc64le.rpm SHA-256: 10cd73f7e7741f8813c47d6e9605e39fc2a4384e03b0f08f4ba3b6866ff79740

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.2.src.rpm SHA-256: cb5b89fd7b2f3bea3b87951375247f42a648e841f4ca4401ca10e06597d3f11a
x86_64
gimp-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: 59bb67dc4c20ddf1f38bfc1c6a257550c9f730bce46f9b69fe1a279f0c1c002d
gimp-debuginfo-2.99.8-3.el9_0.2.i686.rpm SHA-256: 7054d0b55751305920f03962d284eb5e0c19e18d7e80ae189527cec35a63245d
gimp-debuginfo-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: 882f3a29efde3c45baad719b32c7221aabd9829c7b862da8370f2e99c3c8e4f3
gimp-debugsource-2.99.8-3.el9_0.2.i686.rpm SHA-256: f1de69b599c424b94503dc3dae762c088dc870311ceb5118bf0afb729dc0ef81
gimp-debugsource-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: ea3adf9cf59637398496807fb7a0f44523ebe6eb9037fab2e70e17ec3b4e1446
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.2.i686.rpm SHA-256: 280fab31c6f903dfecd489e3778381b95991a61b0e5db5d03a8c1d5eb526f19e
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: adb7d971468a740c8183728aec53b88864d45da8d8d292bb0809ff5fe9347a0e
gimp-libs-2.99.8-3.el9_0.2.i686.rpm SHA-256: e6238f62fceb8c45533e745768fd35cd43db48d1633b0e83236e3d8e3dde3fd4
gimp-libs-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: 74a9892e68a6867de4fddbd32c86ce79df1fec5d49691f3281095b2baa10265d
gimp-libs-debuginfo-2.99.8-3.el9_0.2.i686.rpm SHA-256: b077b4b4579ac8537440ca69ee4f8f91c1082730f6b7afc8f952ca21f19675a1
gimp-libs-debuginfo-2.99.8-3.el9_0.2.x86_64.rpm SHA-256: 5f351e1c3ac874953ef2263db822dad72b36534918c459bcd918d1d33f3bc366

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.2.src.rpm SHA-256: cb5b89fd7b2f3bea3b87951375247f42a648e841f4ca4401ca10e06597d3f11a
aarch64
gimp-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: 089b9a7f7b8bff053cc82fcb7bc832c4909ba0897e655607915d6e9feba0b429
gimp-debuginfo-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: 5b83bae968a63e4282f32875ba7d079195f6a910ef41f04315889589ae85c377
gimp-debugsource-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: 1d5ee2e65d39e230a020c3aed94946e172da811188dbddfcdcbb5acb7e4b80cf
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: dc14f51df01acceefa5ff1aad0dd3a1ede2ec5cc39478aefa1092db186a30b31
gimp-libs-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: 8f9a1480f9eba3d14f36aa2b6d2cfb237c63e3a6f266d20fcb364757deae5748
gimp-libs-debuginfo-2.99.8-3.el9_0.2.aarch64.rpm SHA-256: 03ce916b6255bca367f451ed16d63a335e56db1040aca272f8c2ae14a4ad27ce

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.2.src.rpm SHA-256: cb5b89fd7b2f3bea3b87951375247f42a648e841f4ca4401ca10e06597d3f11a
s390x
gimp-2.99.8-3.el9_0.2.s390x.rpm SHA-256: dfe4909e039f3abf85664a0a474e51b71ae160a3c6ba4237e2d79aba3091e96c
gimp-debuginfo-2.99.8-3.el9_0.2.s390x.rpm SHA-256: 7be241c9249a6d65bdf95008dee02b351ffe4bf6deff168a70e12bc2f47e94f2
gimp-debugsource-2.99.8-3.el9_0.2.s390x.rpm SHA-256: d8ff5b834ec6ed5e7f88acc17c7d54810cdfd1630be711df5c955d3b1ba178c1
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.2.s390x.rpm SHA-256: 456b43a9fd1586050138a5d29d9e6937087bb7fcc21cc64549f401b3410f1467
gimp-libs-2.99.8-3.el9_0.2.s390x.rpm SHA-256: 5916b32b0fe2ac1e5f2e3095fc28302d2f1d1650455f8be298de348d9356cc3c
gimp-libs-debuginfo-2.99.8-3.el9_0.2.s390x.rpm SHA-256: b2a3b5eebdc34568f4e7af092755355c23b422999ea554be137740baf774b2ca

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility