Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2707 - Security Advisory
Issued:
2026-02-16
Updated:
2026-02-16

RHSA-2026:2707 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: heap-based buffer overflow via specially crafted PSP file (CVE-2025-15059)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2432296 - CVE-2025-15059 gimp: heap-based buffer overflow via specially crafted PSP file

CVEs

  • CVE-2025-15059

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
gimp-3.0.4-1.el9_7.3.src.rpm SHA-256: f62de411f656ccfb9ec6b3c14cd76637b098ad429a5fe1aa358f734dbcea6f9f
x86_64
gimp-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: 589334ea71d76ba8bece34d3e5c144755e295130854f0488662331066cf27372
gimp-debuginfo-3.0.4-1.el9_7.3.i686.rpm SHA-256: 17b02e6990ac1069fc1d63944602ed7431403bb5fab7693a7abbe78721260338
gimp-debuginfo-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: 52c0cf8fb1df1fbd762380f68612739cb7cc44194a3d1730441c3f6309eeab82
gimp-debugsource-3.0.4-1.el9_7.3.i686.rpm SHA-256: 48f3c5b8ad712d772cdd715a900286bf7896ecddd1ba5193dcb3b47188769821
gimp-debugsource-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: 0d1020a8a3f1a3b9f87e8ea3df13282417f5b9c9963019c1f84aed01a98d8cfc
gimp-devel-tools-debuginfo-3.0.4-1.el9_7.3.i686.rpm SHA-256: 2f2ef8e179be5f216111f47d219bc4d2f252cfafcaa957730a1ce86936530a9b
gimp-devel-tools-debuginfo-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: 8d11cb87b4c29ab882b6108f411344b58c5977f8a8b50a4207cd9918d7d11aa4
gimp-libs-3.0.4-1.el9_7.3.i686.rpm SHA-256: 99787ab2d9a323c960f81096248246c0c43984e85bc5f2c1b5aa30f23c0342cf
gimp-libs-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: 4501defbbde1c6409263642693b75a881d69c7a7fbbaf8d8f8b788dfb5268a2b
gimp-libs-debuginfo-3.0.4-1.el9_7.3.i686.rpm SHA-256: 6c82e106b7dcad1043de3e8aa55041b00b3324a86a2e77101732a30341eb42c3
gimp-libs-debuginfo-3.0.4-1.el9_7.3.x86_64.rpm SHA-256: bbb601abb0a65d4e3de32ab7ed186b5ce3daf80332570003e4c53ca202d61d1f

Red Hat Enterprise Linux for Power, little endian 9

SRPM
gimp-3.0.4-1.el9_7.3.src.rpm SHA-256: f62de411f656ccfb9ec6b3c14cd76637b098ad429a5fe1aa358f734dbcea6f9f
ppc64le
gimp-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: 90457eb6eb465675c873da7390536791c6ffc7f14f38ac5cd849baee909e953a
gimp-debuginfo-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: 5139e1bec32c53091e4d4f3de1e5e8751948594e2f98fa3cebb5e71c9abc706f
gimp-debugsource-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: ea238835039a8b9bff6675e29c59966836c598bd6b9e9e3c1fd7c993b7a618e7
gimp-devel-tools-debuginfo-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: 3a0ee256bc6a27a0d3e55d2e10e6a72f74e9b66b3361022c24a5a9195accc2fe
gimp-libs-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: 182e743ade5119edcfd792f66ad35377b9612ab9d8f4e7556b40511fde6d30e2
gimp-libs-debuginfo-3.0.4-1.el9_7.3.ppc64le.rpm SHA-256: c4afbdc72a609736ba74708a5e45533283e2ba78780ed6d911104196a252c95b

Red Hat Enterprise Linux for ARM 64 9

SRPM
gimp-3.0.4-1.el9_7.3.src.rpm SHA-256: f62de411f656ccfb9ec6b3c14cd76637b098ad429a5fe1aa358f734dbcea6f9f
aarch64
gimp-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: 54dc15ea41a7a7c4291739a7741bf357844efba3de60b6a158c87f65c65d4b84
gimp-debuginfo-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: 8569abaab6c60cd19176ddbfc544a28c82e3ed62173b055eed8aa0245b235a8b
gimp-debugsource-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: a90033af38d84770de7f88b627b715cd52d6bfd8c9df9e340b6be81f4cbe219e
gimp-devel-tools-debuginfo-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: 9323e80d6eb5e3d796769269f0d384c7c817d32c6f05a41039c1df0fda67bed8
gimp-libs-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: 8945ddda194de0d5bef41a5c36498926b4c1cf9e31021edabbbdf88039ce07d5
gimp-libs-debuginfo-3.0.4-1.el9_7.3.aarch64.rpm SHA-256: 575a6770ab2637d1625cabaa6f5f954986ea720e8c58da9006d2d0ab4a5e19b3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility