Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1585 - Security Advisory
Issued:
2026-01-29
Updated:
2026-01-29

RHSA-2026:1585 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP: Remote Code Execution via PNM file parsing integer overflow (CVE-2025-14422)
  • gimp: GIMP: Remote Code Execution via JP2 file parsing heap-based buffer overflow (CVE-2025-14425)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2424766 - CVE-2025-14422 gimp: GIMP: Remote Code Execution via PNM file parsing integer overflow
  • BZ - 2424767 - CVE-2025-14425 gimp: GIMP: Remote Code Execution via JP2 file parsing heap-based buffer overflow

CVEs

  • CVE-2025-14422
  • CVE-2025-14425

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.3.src.rpm SHA-256: 19a2404cbb6f89d8bdce02f783b25f1b5559b2b29e6a774ab480980c11f84557
ppc64le
gimp-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: 4cfc85678b33f8aaec52c4b94ed0dcb5e0ead3939869985d85179a056ca2b20e
gimp-debuginfo-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: fa4fc9c5f18937498105cfdc808f228db47bf33e958b7b1226c8f69aac6bacd3
gimp-debugsource-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: ea649383e86b3e5630153de0e0bd97ba9ee59c9eda886b7a9ff9c872e4a13865
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: 99d882e4308f09ce10e80a1139314d9a729d54a679edb0af7b0f8ab8be843cd2
gimp-libs-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: fad584d2455e76b75fab362005ecf5094cd79653b388456dd3a291f31c3ba3e3
gimp-libs-debuginfo-2.99.8-3.el9_0.3.ppc64le.rpm SHA-256: d529e0882f28c6ff367366244733f4756c9ef02770b591c7d8fd9ce13fe7334e

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.3.src.rpm SHA-256: 19a2404cbb6f89d8bdce02f783b25f1b5559b2b29e6a774ab480980c11f84557
x86_64
gimp-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: 318b47be92cb310bcf27f046776c240bbcee4e314125bab5809e819da0b15988
gimp-debuginfo-2.99.8-3.el9_0.3.i686.rpm SHA-256: 76970b5d08092834583e62b507b547ad25541e53465f86ef160db03755f91d7e
gimp-debuginfo-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: e7fb27135fde5f082fc99abc86a142909896beccd9cbf728290cc1fead69573a
gimp-debugsource-2.99.8-3.el9_0.3.i686.rpm SHA-256: 0864a74d856bf92db21110175bcb94c4d274082e8816a80f1e5bbc4d2e66e235
gimp-debugsource-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: 9b77c6fa9e8ab8ea5d495c63d802da049bcd087b6b83b8f52acc42494f69ace0
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.3.i686.rpm SHA-256: da41979a39d8216e17569e74f2cae4de2c7d07b5aaa1c7b81d0b7d7558c94e8f
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: 237d62347fc41e83f7ac6b0ae702c7abf6a181a1a50ea3a41f7defeabf087200
gimp-libs-2.99.8-3.el9_0.3.i686.rpm SHA-256: 8c22639c73f35914b73fb7adf5c30c815f96f0975f5acc1d30fc2b66a3afe2f5
gimp-libs-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: ac90c9b82ede87c7d5d8e7952046bef0f81abcaff1866ebe50623cda76db6fa4
gimp-libs-debuginfo-2.99.8-3.el9_0.3.i686.rpm SHA-256: ac604410c2fa632346ad2ee5f44d8c7e7faf04ad03093219590a8112f5f1fd72
gimp-libs-debuginfo-2.99.8-3.el9_0.3.x86_64.rpm SHA-256: e40d86515d6772a59413786a12d250c06ca0e9ce6c7092bab6014e72423fff81

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.3.src.rpm SHA-256: 19a2404cbb6f89d8bdce02f783b25f1b5559b2b29e6a774ab480980c11f84557
aarch64
gimp-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: e8ff4cbecd96541131b1e2ddbbcb03d60e817ba7679ca476f0c2480ff5b41952
gimp-debuginfo-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: e802d78dda10e3317b40d4ab0b12a887888bf2268533e002b9d829af0d3826b0
gimp-debugsource-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: f561ea678f2c4b110e2167a854bd9c0c7303c4391cec815940c58ed1c59491fa
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: 93447580e2d6c20e31734c6eaab894826e0bbd785de2fb58ba4fa15e71368055
gimp-libs-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: 460f33523bd02c1f4ddd4c611c951df3a15f1e29f2dad8403612170f74627fff
gimp-libs-debuginfo-2.99.8-3.el9_0.3.aarch64.rpm SHA-256: c4500a14f2b71608400d46c1cfe91d98b10ff0e6da079a6eb74e4e0c7e96cb65

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.3.src.rpm SHA-256: 19a2404cbb6f89d8bdce02f783b25f1b5559b2b29e6a774ab480980c11f84557
s390x
gimp-2.99.8-3.el9_0.3.s390x.rpm SHA-256: 31afd15734db220c9a4446c7c103180d688795d9af62ed462af01e89aad62310
gimp-debuginfo-2.99.8-3.el9_0.3.s390x.rpm SHA-256: 24a7c8d68f82b1e6ce5143c4c1a15e8e7b85fd4711567bb073ce05a8064e45ac
gimp-debugsource-2.99.8-3.el9_0.3.s390x.rpm SHA-256: ad4d97549e2d259e8c00bfc901f73fafc3a740160742ebf18f9e8156a9309c5b
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.3.s390x.rpm SHA-256: f8a47a1c3696852a4493ef0226e70fae25c8cb1b36bd328fbf5d2d238f39ff10
gimp-libs-2.99.8-3.el9_0.3.s390x.rpm SHA-256: 982b949716e48497ede179235a47f57b0e908de0507283ff2052c2fc91fe6852
gimp-libs-debuginfo-2.99.8-3.el9_0.3.s390x.rpm SHA-256: ec674d9edb495d78ff093635eba6a0d53c440eaffb533c1bfce92b44d8446b39

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility