Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:9315 - Security Advisory
Issued:
2025-06-23
Updated:
2025-06-23

RHSA-2025:9315 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: Multiple use after free in XCF parser (CVE-2025-48798)
  • gimp: Multiple heap buffer overflows in TGA parser (CVE-2025-48797)
  • gimp: GIMP ICO File Parsing Integer Overflow (CVE-2025-5473)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2368557 - CVE-2025-48798 gimp: Multiple use after free in XCF parser
  • BZ - 2368558 - CVE-2025-48797 gimp: Multiple heap buffer overflows in TGA parser
  • BZ - 2370867 - CVE-2025-5473 gimp: GIMP ICO File Parsing Integer Overflow

CVEs

  • CVE-2025-5473
  • CVE-2025-48797
  • CVE-2025-48798

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.1.src.rpm SHA-256: a72c63b2cbaaed2e671c000394b853c63051486e1bc46b39f47785c8dc98f243
ppc64le
gimp-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: 6b5baacc80a2bb15bf320328c4c15896e3fd0920c829ea7ab57920a9560882d7
gimp-debuginfo-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: 2c674d52ebff41f70ddaf5c6d84c8fd898505d2d94c19655dad451410d28f205
gimp-debugsource-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: 0cafb82773152289f4a7f521433833acd99279d8ebfbac43c7bfee149b7d78c1
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: 7c0256383e32de043cc66825c676924d29fca08e309d0283b8e233c5040175ef
gimp-libs-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: 57bda345ff90a8b83a112d7649be8734b370d5a90d518a481b8250010e19a806
gimp-libs-debuginfo-2.99.8-3.el9_0.1.ppc64le.rpm SHA-256: eb409e405989c4018d5081b576a4bb12bc33ed58cad33cb8907a78bb0550f444

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.1.src.rpm SHA-256: a72c63b2cbaaed2e671c000394b853c63051486e1bc46b39f47785c8dc98f243
x86_64
gimp-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: 92c55df9d37af9afb29e77926411d1ea6ad4919fb89b6db50e6da22f54a71569
gimp-debuginfo-2.99.8-3.el9_0.1.i686.rpm SHA-256: 9b5061df8e00287c619326773d041b2d4e8aae89ceee4c7eb132c0a8148b9eb6
gimp-debuginfo-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: 8f2db3ae6521062fe99801ba18aee4c6f11802ed7a6bf2716808563f780cbbca
gimp-debugsource-2.99.8-3.el9_0.1.i686.rpm SHA-256: 71e8673e269864d2ec62cbf99d086e8b25d0c9efe9ca521a140b52448802fb90
gimp-debugsource-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: faf00014831406f7186611d59a5fbbf1cf1d7fd552cc846263a7c7b93d349499
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.1.i686.rpm SHA-256: 41ca49ff5ac19519eb99f86cacbfb7cb903298a54e562e3216155eaf7b88a07c
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: 1054233a6e6259f3b0e58c94ce0ce49e1095157222f93fa4abf27e43bf0131cb
gimp-libs-2.99.8-3.el9_0.1.i686.rpm SHA-256: ca5baf5c08433470b14a4e445ca6a9f2db180d74cd79e7977caf8e0a4b0d186f
gimp-libs-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: 89fc69e002dcd9c1fe0cab307651d5672153e2706edd9a9bd7b30b650a5ea6fb
gimp-libs-debuginfo-2.99.8-3.el9_0.1.i686.rpm SHA-256: 91fa39ad62c9d8ede7dd84efa558de3f8bedde78656e260fc936f6ee8d471ff5
gimp-libs-debuginfo-2.99.8-3.el9_0.1.x86_64.rpm SHA-256: 055e0df98cc327920c06dbcd7c422a4cf6e8ef293d97bc5aeb58d30f547ef40e

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.1.src.rpm SHA-256: a72c63b2cbaaed2e671c000394b853c63051486e1bc46b39f47785c8dc98f243
aarch64
gimp-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: 0c350f1430d26d7caa0a459f72fd343983a461527a91cab7abab664e0edb0823
gimp-debuginfo-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: 2cacea4132108eed1ce2bca451922193158cb7476270e6b876e2bb93ae542c5a
gimp-debugsource-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: c175c50554634384a10c58a4716751eaf6624e0638d417735d69f38b084c2277
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: df20d601dca50111ec66e4648c9ff9fc65409280884f2637fb9d946fb0a19f26
gimp-libs-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: dad420189db45d427a19e572b0a75689ad454446d4f64071e0a2762494d08e72
gimp-libs-debuginfo-2.99.8-3.el9_0.1.aarch64.rpm SHA-256: 50fa3ffcf8ec81be8fb39de05542595574c0336ae78d7442736b445d189b530e

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.1.src.rpm SHA-256: a72c63b2cbaaed2e671c000394b853c63051486e1bc46b39f47785c8dc98f243
s390x
gimp-2.99.8-3.el9_0.1.s390x.rpm SHA-256: 92fb87da2f8730c35b26d9e2ae234aba1a2be9138c43ace02857d59762e46f67
gimp-debuginfo-2.99.8-3.el9_0.1.s390x.rpm SHA-256: 5bcb72ef828a72536e328055da1e047878f47640d4f89d670ae2b78c74c1b5e0
gimp-debugsource-2.99.8-3.el9_0.1.s390x.rpm SHA-256: d790c052143296484e1d7bb05086d278b7ad59ea961ae1a9c8d4559b2d055456
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.1.s390x.rpm SHA-256: 141dc80d5e64c3bff58cd9eccaeeda222e257e9bd4e9aaa26f26cb04e5943441
gimp-libs-2.99.8-3.el9_0.1.s390x.rpm SHA-256: f2681507829c538aa3e89332fafca498790ca9d759cc7d777cf1fa2788d151f7
gimp-libs-debuginfo-2.99.8-3.el9_0.1.s390x.rpm SHA-256: 12e55ffdcee43db30de3ce10a13ceaf3b8704cd6daccb6cadf8a674ee7aac1f8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility