Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:9310 - Security Advisory
Issued:
2025-06-23
Updated:
2025-06-23

RHSA-2025:9310 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp:2.8 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the gimp:2.8 module is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: Multiple use after free in XCF parser (CVE-2025-48798)
  • gimp: Multiple heap buffer overflows in TGA parser (CVE-2025-48797)
  • gimp: GIMP ICO File Parsing Integer Overflow (CVE-2025-5473)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 8.2 x86_64

Fixes

  • BZ - 2368557 - CVE-2025-48798 gimp: Multiple use after free in XCF parser
  • BZ - 2368558 - CVE-2025-48797 gimp: Multiple heap buffer overflows in TGA parser
  • BZ - 2370867 - CVE-2025-5473 gimp: GIMP ICO File Parsing Integer Overflow

CVEs

  • CVE-2025-5473
  • CVE-2025-48797
  • CVE-2025-48798

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 8.2

SRPM
gimp-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.src.rpm SHA-256: 098c08c4ba486ed167776a982271d84d08aaebea7c5f430167c92cadadc88f44
pygobject2-2.28.7-4.module+el8+2760+3d7d61b2.src.rpm SHA-256: 89161d4acfb1217dcc5b4ea4e232eeb8b40d9744cf9c8785ff0183eb4ce1ccb1
pygtk2-2.24.0-24.module+el8+2760+3d7d61b2.src.rpm SHA-256: 64c448d7f24184438508a509686d6bd4027dbe0095ca64d7d0308c7fd012877c
python2-pycairo-1.16.3-6.module+el8+2760+3d7d61b2.src.rpm SHA-256: a56385f162203977deddcf0988d03e5c98855fa3b6bae176eab07ccbf04c8855
x86_64
gimp-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: 4da3a4076221ffbf880bfb3a2b4b3b715d79a1a36720db68862d9dcd7f7ff8ed
gimp-debuginfo-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: fbb133954f8f70cffc2483d507cda73eed05376efa03dfb5edefe45bc9f0f621
gimp-debugsource-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: cd070dada1bf9eeb12000bfc5a193023fd4d2100490cd789317cc35e2f2a40c0
gimp-devel-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: ac44b40f89e66bedbe92517a722e2132094a588e948a42240e263d610759f8ba
gimp-devel-tools-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: 9d0c656370c27da55b95ff1bb8789cb470f2f22604a3117a1f50e51b2ee04d05
gimp-devel-tools-debuginfo-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: 7ace2d91feaa1669cc2ec4d0118c4e505217845e737c2a3b3a2738c589e29f70
gimp-libs-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: c9bfa51aafd254d92af7dbb84d494b5d1b8c85323c15be07f4ad16507d557bb2
gimp-libs-debuginfo-2.8.22-16.module+el8.2.0+23304+5410b5dc.3.x86_64.rpm SHA-256: 38d3a60a12a5ea9f9113e391d3107ffd4e42cfd641e980134ce763b7a797e776
pygobject2-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 0722e0e1eace67230b3b2285cc4d12e0b801510a61a73227d9afafe3c44e4fd4
pygobject2-codegen-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 7b174815b7d3d9d63c6f06a9b9fe9a459b18b1a8fc9d80a2be41d405d9fee116
pygobject2-debuginfo-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 88ebab5bfedabdfdbe90c7bf85189475d98d2b2baf99ced111d0be75c0afa79b
pygobject2-debugsource-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 377c821e30723f72e4181bd3e1d7ec7ea6462a269ec155a9b550017910cdeb12
pygobject2-devel-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 612cbce7dfde755d5979b06e47bc9833d9031abb5eec8dbecb510b71222d623d
pygobject2-doc-2.28.7-4.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 238b8c2d865f299dcaae6eb3efa70107f95f4df96fbaaecb27a07afcb584618a
pygtk2-2.24.0-24.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 90a8290e06e40444323584b86814fe78c4920cb8c0c620a56184b7a05a1d24bf
pygtk2-codegen-2.24.0-24.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: cab5d098f3c2debebd3bec5d0703cabc6fdb6c18d93ae54bfa709d2f348725eb
pygtk2-debuginfo-2.24.0-24.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 163c6c9d8f42a162b9ed7aa70a98f4766654e6a3ea22955c018eeb43873fa5fd
pygtk2-debugsource-2.24.0-24.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: af0820b372cd77e1447431499c8bfe0fc389ff2f6765421a9d0d146fa578da87
pygtk2-devel-2.24.0-24.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: cc93b02deafb6a321aac24aaab257b5589894032e62962572536f42a603731ab
pygtk2-doc-2.24.0-24.module+el8+2760+3d7d61b2.noarch.rpm SHA-256: ed03b9f39c9bd053dfa80ddf2bac15fa8257dd4d61f18c62211689fe6c9c0ddb
python2-cairo-1.16.3-6.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: ce2b513387d5224348d45ac7cf927a8bbdb18b7999bf43a177c6d10838c95ee8
python2-cairo-debuginfo-1.16.3-6.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: f9a92ae5992e1a3af804aaa8f6bc259a982aa419c099f7d0e1913f2ec12b5642
python2-cairo-devel-1.16.3-6.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 429a1a2f6d367c4eed3ed8411427f2ab99c00f90f2d5a4de0e78d10cd48baa09
python2-pycairo-debugsource-1.16.3-6.module+el8+2760+3d7d61b2.x86_64.rpm SHA-256: 61abdc30c8d7b66346678ea20f88dd31ef426da5a3e7314aafa0cbaa892b35ba

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility