Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22498 - Security Advisory
Issued:
2025-12-01
Updated:
2025-12-01

RHSA-2025:22498 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10922)
  • gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10934)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2407188 - CVE-2025-10922 gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • BZ - 2407233 - CVE-2025-10934 gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVEs

  • CVE-2025-10922
  • CVE-2025-10934

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
gimp-2.99.8-4.el9_2.2.src.rpm SHA-256: 2b2d3346163a54575b5913f73a67cef6193e5ecd9e3c42cde5c833647fe1661f
x86_64
gimp-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: fe00ac45c7347124c85d86821f76d0200cdd6234f2528128e0c59c30f944ceb8
gimp-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: c5b7778ee619770845e685bc9fd8a4b8b9c40b00f435aeae7e996b393012b540
gimp-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 08ddae581d4bebf659525b62b507b6699c750e2d15ea6c0d4169b38b68c7d0e0
gimp-debugsource-2.99.8-4.el9_2.2.i686.rpm SHA-256: 4ba5de755f74f354f4bfb4b992f0ed218a8dd820f6df7368f5926e827305dccf
gimp-debugsource-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 922e99abd0f36234de9049a1aa5599090842bc51683aa92e45db1768651552b7
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: c462ae93d225bf812139c812a3db929a35be9f8694a651a85aa15705a7d93ac1
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: e94c968f0ba4fe82d97a6d46257dfbaa44a2ae1fe93adc4989dd0b63fc063f13
gimp-libs-2.99.8-4.el9_2.2.i686.rpm SHA-256: 8dab8bdb6cd2c0066abc236b5a4d4ecfb34d3c7e64adea32bbf793bfd4f75800
gimp-libs-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 60ef3d6ca87d44c5da68dd6cc207607704d3ef85d705bd3f9f87924499102548
gimp-libs-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: 4a401f9db83246a3f607d5ee9b43d937327fa5efd2a1add4e88103cb8e9c1b9d
gimp-libs-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: b15f03ef1dcc6bb162053a12e152eb330f81e5f31a380a84c3c43eddc672de89

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
gimp-2.99.8-4.el9_2.2.src.rpm SHA-256: 2b2d3346163a54575b5913f73a67cef6193e5ecd9e3c42cde5c833647fe1661f
ppc64le
gimp-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: 55af4e0ee2071a7f04a71ccfc3cebdb579f8b6493881b27af1fb787f34416aa2
gimp-debuginfo-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: ef46fe5f4d3d57f42558dce8fb926caac9a4fb6cac1a0f5d86054af41ab9a9bf
gimp-debugsource-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: f00b14b6afb064a39e22f61ab2984c6e2041b821083a6f2ddf6140fc01c5a1d1
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: 6e613a5e68f092ddc429dba8e4288a7afc6ab644e020ad539eeaac42a13bcbf2
gimp-libs-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: e7e3c22bbc820bbb98658ed15739b0edf9166045778298da93c74489cad816e6
gimp-libs-debuginfo-2.99.8-4.el9_2.2.ppc64le.rpm SHA-256: 0c4e763bad0c9d168ced4531c087f614c828a9447b9eea0cdca36b290019c9f1

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
gimp-2.99.8-4.el9_2.2.src.rpm SHA-256: 2b2d3346163a54575b5913f73a67cef6193e5ecd9e3c42cde5c833647fe1661f
x86_64
gimp-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: fe00ac45c7347124c85d86821f76d0200cdd6234f2528128e0c59c30f944ceb8
gimp-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: c5b7778ee619770845e685bc9fd8a4b8b9c40b00f435aeae7e996b393012b540
gimp-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 08ddae581d4bebf659525b62b507b6699c750e2d15ea6c0d4169b38b68c7d0e0
gimp-debugsource-2.99.8-4.el9_2.2.i686.rpm SHA-256: 4ba5de755f74f354f4bfb4b992f0ed218a8dd820f6df7368f5926e827305dccf
gimp-debugsource-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 922e99abd0f36234de9049a1aa5599090842bc51683aa92e45db1768651552b7
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: c462ae93d225bf812139c812a3db929a35be9f8694a651a85aa15705a7d93ac1
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: e94c968f0ba4fe82d97a6d46257dfbaa44a2ae1fe93adc4989dd0b63fc063f13
gimp-libs-2.99.8-4.el9_2.2.i686.rpm SHA-256: 8dab8bdb6cd2c0066abc236b5a4d4ecfb34d3c7e64adea32bbf793bfd4f75800
gimp-libs-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: 60ef3d6ca87d44c5da68dd6cc207607704d3ef85d705bd3f9f87924499102548
gimp-libs-debuginfo-2.99.8-4.el9_2.2.i686.rpm SHA-256: 4a401f9db83246a3f607d5ee9b43d937327fa5efd2a1add4e88103cb8e9c1b9d
gimp-libs-debuginfo-2.99.8-4.el9_2.2.x86_64.rpm SHA-256: b15f03ef1dcc6bb162053a12e152eb330f81e5f31a380a84c3c43eddc672de89

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
gimp-2.99.8-4.el9_2.2.src.rpm SHA-256: 2b2d3346163a54575b5913f73a67cef6193e5ecd9e3c42cde5c833647fe1661f
aarch64
gimp-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 90caf5fd4e87d2bef6abd5b69727552e0abc3b39fe301bfe1be2f55d6b336470
gimp-debuginfo-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 20165a9773abf700c0d116ea8611cf218bb47570ad57e9933f630f7265af4cfd
gimp-debugsource-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 5cbdca7830983623668d0c56d7418b0e256ae99ba3664260d5a9fe8c123f3480
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 2d7f79a1d602ec056fd9ab5c12f75faf1922b8765a7a612dc9539d394ed67981
gimp-libs-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 528eb86a2281f48e5d5996ace05c13364f90265afc3a41dadefccf97fe617f16
gimp-libs-debuginfo-2.99.8-4.el9_2.2.aarch64.rpm SHA-256: 26850263f1323acbe82f4a9589130f6020d3c885339ef25d4efc898e4d73a070

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
gimp-2.99.8-4.el9_2.2.src.rpm SHA-256: 2b2d3346163a54575b5913f73a67cef6193e5ecd9e3c42cde5c833647fe1661f
s390x
gimp-2.99.8-4.el9_2.2.s390x.rpm SHA-256: 815eff725d042fc1f0baca298b56e4b26af91d3d440a979bcfa758e54ca35b87
gimp-debuginfo-2.99.8-4.el9_2.2.s390x.rpm SHA-256: 23fb90860e4559eff0d77f29616f62db8fc5d3eb0c6e06099231e2976c2f7d12
gimp-debugsource-2.99.8-4.el9_2.2.s390x.rpm SHA-256: 3dbd696e73b47c40a31cd143890576572ab87d1469730ad08ed5fbf04b418ffa
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.2.s390x.rpm SHA-256: a2c4da254e13ac26f34bc24ed0166151efc59ad306722de1caca4d98019fb169
gimp-libs-2.99.8-4.el9_2.2.s390x.rpm SHA-256: b9e8c0c5144aab02d5c4d7f301b9deac593fc621b4f45732cdcc74bdb294d901
gimp-libs-debuginfo-2.99.8-4.el9_2.2.s390x.rpm SHA-256: 4acc031e01437b0c2bdb8ddbce30030e8915fbc2fff987fd4627e563bcbcd20d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility