Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22866 - Security Advisory
Issued:
2025-12-08
Updated:
2025-12-08

RHSA-2025:22866 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10922)
  • gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-10934)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2407188 - CVE-2025-10922 gimp: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • BZ - 2407233 - CVE-2025-10934 gimp: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVEs

  • CVE-2025-10922
  • CVE-2025-10934

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
gimp-2.8.22-1.el7_9.4.src.rpm SHA-256: 3471ef33ef0dc042c17f8dab2358f11cd8ff4a06af5951a433e2c13e7789c56c
x86_64
gimp-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: 67105e9ed86c59445a03941688622f561aedbdf5042ac02bc1dec83d520e87d9
gimp-debuginfo-2.8.22-1.el7_9.4.i686.rpm SHA-256: e576d55f2fcc088c95ad47ada3ab421009284add3dc556029e7dce7268540e9e
gimp-debuginfo-2.8.22-1.el7_9.4.i686.rpm SHA-256: e576d55f2fcc088c95ad47ada3ab421009284add3dc556029e7dce7268540e9e
gimp-debuginfo-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: 6ecc7d7f5b9e7c17195e595fc76c31989d49202d53ac10710173a76027b013d4
gimp-debuginfo-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: 6ecc7d7f5b9e7c17195e595fc76c31989d49202d53ac10710173a76027b013d4
gimp-devel-2.8.22-1.el7_9.4.i686.rpm SHA-256: 65447b3b7b376f15d6abc675cda333ccea590b54b13a4a1d33ee6229408bffbc
gimp-devel-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: 705fc12aadb215ea3866e3d814ea15abc03639fd50306b266ad54935abd4b476
gimp-devel-tools-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: 07f91398d4eb9bd946761656e85677a02f18f3164df56ac64e5fb2bd21d67322
gimp-libs-2.8.22-1.el7_9.4.i686.rpm SHA-256: d52e9e49c9a94af943d89028d5434e50ae26d3965736e558275cd5073122b327
gimp-libs-2.8.22-1.el7_9.4.x86_64.rpm SHA-256: b458eb07ec7ec7be22640e278d52c21e2a137a2f7a51678158e144acbeb5ede8

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
gimp-2.8.22-1.el7_9.4.src.rpm SHA-256: 3471ef33ef0dc042c17f8dab2358f11cd8ff4a06af5951a433e2c13e7789c56c
s390x
gimp-2.8.22-1.el7_9.4.s390x.rpm SHA-256: adeb6db5a29613c096953da2d9eeb3710c9351d353da2ebff2e318da5dec617b
gimp-debuginfo-2.8.22-1.el7_9.4.s390.rpm SHA-256: 7a2ba663d669fa83470280856e1a4989d8357385d92714a9746409dee231b20c
gimp-debuginfo-2.8.22-1.el7_9.4.s390x.rpm SHA-256: 3006012d24a3a907a1056093f3f08471673c03f83e0ed4220427d8370e1114d3
gimp-devel-2.8.22-1.el7_9.4.s390.rpm SHA-256: 69d95f8afce79f837bfea952c31d03f53aae69eef41e04de557284c3c3d7917f
gimp-devel-2.8.22-1.el7_9.4.s390x.rpm SHA-256: b422851e2e7f15944eb0c0a761f3b2faae58bbac623291dafd5a12e1a3ea7134
gimp-devel-tools-2.8.22-1.el7_9.4.s390x.rpm SHA-256: 39f9014b92a12c39f8f8691c247d6064051ef9cdfe7c6867dc730d4cb140b701
gimp-libs-2.8.22-1.el7_9.4.s390.rpm SHA-256: f1614be05e7b98de5fc8978b12a74ca127a678b9547226cd67af437f5ed9ad8b
gimp-libs-2.8.22-1.el7_9.4.s390x.rpm SHA-256: 39085cf6c208887b6d91e355477b08a755de2a93cba17163e382229d1db575c5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
gimp-2.8.22-1.el7_9.4.src.rpm SHA-256: 3471ef33ef0dc042c17f8dab2358f11cd8ff4a06af5951a433e2c13e7789c56c
ppc64
gimp-2.8.22-1.el7_9.4.ppc64.rpm SHA-256: 9c0e188aa97b0ad837ba757c6be8bd673a69f491caecd7abecbb568f08e627a5
gimp-debuginfo-2.8.22-1.el7_9.4.ppc.rpm SHA-256: 843e626e3c50ace8d8dffb91a6ef62da5c89904d1d49f7879ca958ecc0e7ed21
gimp-debuginfo-2.8.22-1.el7_9.4.ppc64.rpm SHA-256: bfa7eb8840dc8406b9292f6556b6a7208d02a04a28346d3cb7017312f0ee58b5
gimp-devel-2.8.22-1.el7_9.4.ppc.rpm SHA-256: 3309bd5ba5ec5fb7c789e55e0c79187f96f4acb0c2920272c4a2ab5b59d78f3c
gimp-devel-2.8.22-1.el7_9.4.ppc64.rpm SHA-256: 6509891046b61c376f3ea08057a7201cdec31a0bd65530e38ed28fd10d8c7ea9
gimp-devel-tools-2.8.22-1.el7_9.4.ppc64.rpm SHA-256: f6ac8642529c22421daa0ae03b47106bfa94e93d35ce64ab31bd8cdc6111f27a
gimp-libs-2.8.22-1.el7_9.4.ppc.rpm SHA-256: 8323447d8cd26133a022f5c19a388e4cc3df1c802e14da9ffea9cb8e4aae98d7
gimp-libs-2.8.22-1.el7_9.4.ppc64.rpm SHA-256: b8b3a5d3f48ab8d477042c360e2be603ee65d8ee1108f90bad3d08cf8cfe64fa

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
gimp-2.8.22-1.el7_9.4.src.rpm SHA-256: 3471ef33ef0dc042c17f8dab2358f11cd8ff4a06af5951a433e2c13e7789c56c
ppc64le
gimp-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 3c24cc01129aa412138968492eab39d30c3d49c448dbe02811e55cb096df27c9
gimp-debuginfo-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 95a4bff1e8b64917b1cf7af972662333056f78f187ec8c38022e1354f67ab5d2
gimp-debuginfo-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 95a4bff1e8b64917b1cf7af972662333056f78f187ec8c38022e1354f67ab5d2
gimp-devel-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 93a612576f4326edc1261c54c09448fa1d52e31d1433de9d408f22d5553e22eb
gimp-devel-tools-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 03d9dd3ed032f719aa6c65006388d18c24f44f2da5865e33821249d51d37c483
gimp-libs-2.8.22-1.el7_9.4.ppc64le.rpm SHA-256: 8619b3d28bcf968c52ea12057946ee90448aee6ef7dd6a27c0d497352c6f505d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility