Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1590 - Security Advisory
Issued:
2026-01-29
Updated:
2026-01-29

RHSA-2026:1590 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP: Remote Code Execution via PNM file parsing integer overflow (CVE-2025-14422)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2424766 - CVE-2025-14422 gimp: GIMP: Remote Code Execution via PNM file parsing integer overflow

CVEs

  • CVE-2025-14422

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
gimp-2.8.22-1.el7_9.5.src.rpm SHA-256: 9ee068b3f7ae3085d42a6007294d95e2570b3f80c2709c41f18125b5f0039b4b
x86_64
gimp-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: 0162e92e2358ebbe0aefee2908a62e1449e54bc2df123505d5116f316c16f159
gimp-debuginfo-2.8.22-1.el7_9.5.i686.rpm SHA-256: efc693eac281ce8b0b04ef5932e6784f24019e2ff2046c8b03a53ab79df80528
gimp-debuginfo-2.8.22-1.el7_9.5.i686.rpm SHA-256: efc693eac281ce8b0b04ef5932e6784f24019e2ff2046c8b03a53ab79df80528
gimp-debuginfo-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: 5f98e89817cfcc2336c12d0fa9cc32af5ca9463c26a7329b55bec51d2ce4b75d
gimp-debuginfo-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: 5f98e89817cfcc2336c12d0fa9cc32af5ca9463c26a7329b55bec51d2ce4b75d
gimp-devel-2.8.22-1.el7_9.5.i686.rpm SHA-256: e40b4f4b54bf0b714d841f8b2d5d8a164a85ee03375faf4fd09d7120fd27dfa8
gimp-devel-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: f2d8dd691856a48f4d4173fb94cb71a76d13762ac1a0aaf23b91c3a159e62756
gimp-devel-tools-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: 490d4aa349c8cdfc37bb5c256ec4aef902859462ca268c46dcad1170a313a8be
gimp-libs-2.8.22-1.el7_9.5.i686.rpm SHA-256: ec596e261149b738173c6341871429c5fdc7cb9f97815ffb4821cfae3c99400a
gimp-libs-2.8.22-1.el7_9.5.x86_64.rpm SHA-256: 332ee59a9fcf27c5b5b5b5fbe88a80c075d1f78c509ccd5525e01165717ddde5

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
gimp-2.8.22-1.el7_9.5.src.rpm SHA-256: 9ee068b3f7ae3085d42a6007294d95e2570b3f80c2709c41f18125b5f0039b4b
s390x
gimp-2.8.22-1.el7_9.5.s390x.rpm SHA-256: 159794a3216e9eeda841a22920ad1c5fa03fc798d8a936b92afa769123a65b8c
gimp-debuginfo-2.8.22-1.el7_9.5.s390.rpm SHA-256: 7a172c30330471af239dd2e99a0acfaba612a432c1c8190bff65f37ed066a1b6
gimp-debuginfo-2.8.22-1.el7_9.5.s390x.rpm SHA-256: c9d87a2f4b0573b57be79379b9db74cac5fa7737a1d022a6c287ef4dd877051b
gimp-devel-2.8.22-1.el7_9.5.s390.rpm SHA-256: a462b79ec070c99b2ae8e8baf51da906d0c1774ab6508fe51747d64815f48136
gimp-devel-2.8.22-1.el7_9.5.s390x.rpm SHA-256: 0ad387068c278ec564d1d96bcb7b27fc2389a35e5cf3e8f5d84e832eeeb246e8
gimp-devel-tools-2.8.22-1.el7_9.5.s390x.rpm SHA-256: 4cdbfcc645eac554f1b92451c38be9a71da0a111a54c22355dac822bf6cd2052
gimp-libs-2.8.22-1.el7_9.5.s390.rpm SHA-256: 7e68dc8ccf80ee0fb8664c06ef1bce95a62a27b99c61eb6dd2f1b1a2cac0ad93
gimp-libs-2.8.22-1.el7_9.5.s390x.rpm SHA-256: 4c6b4af9af99369e53ee34e905640774b10a19bec02b0cfc48c465b62af30ea8

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
gimp-2.8.22-1.el7_9.5.src.rpm SHA-256: 9ee068b3f7ae3085d42a6007294d95e2570b3f80c2709c41f18125b5f0039b4b
ppc64
gimp-2.8.22-1.el7_9.5.ppc64.rpm SHA-256: 73eacdebbbf66637e38f3f3cb361be52dd7e2c12519d7777489c47f1b2218ead
gimp-debuginfo-2.8.22-1.el7_9.5.ppc.rpm SHA-256: 7ffaf722ed39274ada9ae0b4cf3a48f323c1db7cdd3007651dc498bde68ac26f
gimp-debuginfo-2.8.22-1.el7_9.5.ppc64.rpm SHA-256: ab2447c1ae8dae5262c7cbc7ce6e589b3c6fac0a1067229d4960e2fd440d8a99
gimp-devel-2.8.22-1.el7_9.5.ppc.rpm SHA-256: 4837eb35d345b44a5fdf1a670e380c55159250ed6c52c19f8a9cec79ac51d6aa
gimp-devel-2.8.22-1.el7_9.5.ppc64.rpm SHA-256: b6268f16ace8bcc56da20b9bdbef75b8f96a2e59075176a4e1ca2fa33a73abb3
gimp-devel-tools-2.8.22-1.el7_9.5.ppc64.rpm SHA-256: 68d5c7b24892202e82e5cde8fdecab9c559eb816128dcb9534055a256e66fcc9
gimp-libs-2.8.22-1.el7_9.5.ppc.rpm SHA-256: 89044798550c943e8e6aec0e441c6836a33396cd1d9a8686cefe23544fc8c2c6
gimp-libs-2.8.22-1.el7_9.5.ppc64.rpm SHA-256: a2e9d4efae5842cfb6701977d6c3d3ec2e12d683c6581aaf72e8667d5a36ed08

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
gimp-2.8.22-1.el7_9.5.src.rpm SHA-256: 9ee068b3f7ae3085d42a6007294d95e2570b3f80c2709c41f18125b5f0039b4b
ppc64le
gimp-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 157508674c1b0c6eab3494bee5f17febc0151f07fc82828a1f4ff25dffcae711
gimp-debuginfo-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 6a2a1d979f771a2e2448265e5b117bd34a3129f1f0b02e0ecde0758e4ac66ef1
gimp-debuginfo-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 6a2a1d979f771a2e2448265e5b117bd34a3129f1f0b02e0ecde0758e4ac66ef1
gimp-devel-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 1f2dc1bc30f271a618b317577d1a8f7e5772c6bcba6c68a191a167ee8a6ac212
gimp-devel-tools-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 4aca7e70f33cb665ca16035f725f99caa6711e8b8bb967a3b7a54756dd1b0bb1
gimp-libs-2.8.22-1.el7_9.5.ppc64le.rpm SHA-256: 7297294ad8611ee118d22982779cfd98c4bdd85d19446d2fa632c3a11b74afc5

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility