Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2969 - Security Advisory
Issued:
2026-02-18
Updated:
2026-02-18

RHSA-2026:2969 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: heap-based buffer overflow via specially crafted PSP file (CVE-2025-15059)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2432296 - CVE-2025-15059 gimp: heap-based buffer overflow via specially crafted PSP file

CVEs

  • CVE-2025-15059

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.4.src.rpm SHA-256: c22e91836cdf993c32ba1e81ba12fbaa9eaf6dadb55719736d0f3563c065ad10
ppc64le
gimp-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: dba23e7f121abee75305550bde8937b9d2a0d5e681c69846c14bb2435c42893f
gimp-debuginfo-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: 65c8768bde4e292f6a05c261d40617ced0f4db53f26ff9a0d47ba9849c73f0bf
gimp-debugsource-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: 085479da507c7ca4810c6904da3e6076eec33fd32f78813fd28db2fc4e4336bf
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: 600747cf5d71404edf269bad0b664cd8509a44f3fcd901cef2c41242a9899987
gimp-libs-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: 58a6b67fd1799f30690e1140394e6687894d6131abf38ab9de6a19acc541d8f5
gimp-libs-debuginfo-2.99.8-3.el9_0.4.ppc64le.rpm SHA-256: 5e761e10e3069ae7b997a12dae167e46243844b36a77a87e8a75c34ffd33d6d3

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
gimp-2.99.8-3.el9_0.4.src.rpm SHA-256: c22e91836cdf993c32ba1e81ba12fbaa9eaf6dadb55719736d0f3563c065ad10
x86_64
gimp-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: 5bc5ce6f562b84ac37604f953cb621b4e7d2f1bd853a622bb39687f931b8e57f
gimp-debuginfo-2.99.8-3.el9_0.4.i686.rpm SHA-256: 90faefa62dd435ca802dd3471f507ffc9cf034dc07892bd585d94cad59f96059
gimp-debuginfo-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: b5b10c6bbb50069f13563053d15275c7870cb9b67f44822752a56da734c0b411
gimp-debugsource-2.99.8-3.el9_0.4.i686.rpm SHA-256: fc5ab1b0069bc727623374f79a607f144074da5c304436c67e9aa369bcc41386
gimp-debugsource-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: 0b3baeadb5827344d9ce6fd5bf86f4d309273306a6dece85ccbe163546bf08fb
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.4.i686.rpm SHA-256: 73831f43ebb227946ffaf9a614d88286061ea86fbce8f85ec750248c699364fa
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: e2b5bcabac0d91ac9f8454864bf7895cafa66e07e6755f70d3035e8965d14503
gimp-libs-2.99.8-3.el9_0.4.i686.rpm SHA-256: fe918c34b0ac3ac1ef483c207a00abdec17104cacbdbacd91992c6b7c144e324
gimp-libs-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: 047f43a18fd5ed83d7806add2bcc8d32fd531396a74773c33988a7de1566cec7
gimp-libs-debuginfo-2.99.8-3.el9_0.4.i686.rpm SHA-256: 7fa0b22217c601d50c0fa472853a12372c5d651dcacc31dbeff789e867552510
gimp-libs-debuginfo-2.99.8-3.el9_0.4.x86_64.rpm SHA-256: 7c576bb1dc0ef55d14f5a87dce8878fb1564570e3c3613bf21c8dc2b92491ac2

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.4.src.rpm SHA-256: c22e91836cdf993c32ba1e81ba12fbaa9eaf6dadb55719736d0f3563c065ad10
aarch64
gimp-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: e7f12526c7f5168f6e047da017a0d31de30a9759ea1d59ecc540561b1553f024
gimp-debuginfo-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: 40f10f49a932daff7795525f0394e7ec0d29e4d8d7efa57d171ef1fbab2cd910
gimp-debugsource-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: ac0551ea813069f6f7976f5b79b2804560cf7cc929f9da0ffdc7f5a3fe7fd829
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: a194b3a2fbe96063d408426f4621c3045a56490ea83d2ddfe00291740162394a
gimp-libs-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: fe08130f6e4aac61803deb5171406d19833a22bf6d2b4efe12f990eadfc7381a
gimp-libs-debuginfo-2.99.8-3.el9_0.4.aarch64.rpm SHA-256: 024a9c3f086eaf1674b5de32408a003119085c9797bf860e2aa2a05343bcf005

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
gimp-2.99.8-3.el9_0.4.src.rpm SHA-256: c22e91836cdf993c32ba1e81ba12fbaa9eaf6dadb55719736d0f3563c065ad10
s390x
gimp-2.99.8-3.el9_0.4.s390x.rpm SHA-256: a36c06fa1ed862a5ea8308c59d1e9dc3b0c4a9f386d094f7c4cb22913c9112bd
gimp-debuginfo-2.99.8-3.el9_0.4.s390x.rpm SHA-256: 0a50e1b53a8b7ede4abe857283fbb2a7a6fe11c2f5f4e856a222f4c52338b408
gimp-debugsource-2.99.8-3.el9_0.4.s390x.rpm SHA-256: 9e3edfdc49ee8e4c29380ace6b377134893d78596397da1ff17ebc159b830467
gimp-devel-tools-debuginfo-2.99.8-3.el9_0.4.s390x.rpm SHA-256: d3daf889a86eecda4df9d9aaebfa13ba604165a8fe4dee104b18fce0ef7bda39
gimp-libs-2.99.8-3.el9_0.4.s390x.rpm SHA-256: b73c112560c2eae0bb2a4d13999d0b3960d1b6db34a40603b18206a5e9ac9058
gimp-libs-debuginfo-2.99.8-3.el9_0.4.s390x.rpm SHA-256: 756cb62909d9c677ac4d37272af8fef1596dd4ddfda7d77a305cd6b3f0861358

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility