Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5389 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5389 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: gimp security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for gimp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo.

Security Fix(es):

  • gimp: GIMP: Remote Code Execution via uninitialized memory in PGM file parsing (CVE-2026-2044)
  • gimp: GIMP: Remote Code Execution via out-of-bounds write in XWD file parsing (CVE-2026-2045)
  • gimp: GIMP: Remote Code Execution via ICO File Parsing Vulnerability (CVE-2026-0797)
  • gimp: GIMP: Remote Code Execution via XWD file parsing vulnerability (CVE-2026-2048)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2441521 - CVE-2026-2044 gimp: GIMP: Remote Code Execution via uninitialized memory in PGM file parsing
  • BZ - 2441522 - CVE-2026-2045 gimp: GIMP: Remote Code Execution via out-of-bounds write in XWD file parsing
  • BZ - 2441524 - CVE-2026-0797 gimp: GIMP: Remote Code Execution via ICO File Parsing Vulnerability
  • BZ - 2441527 - CVE-2026-2048 gimp: GIMP: Remote Code Execution via XWD file parsing vulnerability

CVEs

  • CVE-2026-0797
  • CVE-2026-2044
  • CVE-2026-2045
  • CVE-2026-2048

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
gimp-2.99.8-4.el9_2.5.src.rpm SHA-256: 0f2f317be6a520271c162f294e8d5a7e3b8e31d61fcd9e7bbcb23df08ef8441d
x86_64
gimp-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: e63e84a3bb206f5b1e86e13ae04f3d74d269b540da75c3a526176a72135c2056
gimp-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: fbc52aecad5bd7af996b8041c49c811eb4935717061c765f31b284c1305d085a
gimp-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 025caa65cd863fcf7af8b9183fff78de4caaf47b3abfae4af866b45b3bdf7a96
gimp-debugsource-2.99.8-4.el9_2.5.i686.rpm SHA-256: 6bc5297b4adba658a4818b787455dffd2ace80b86a522f85f92010fe416c437b
gimp-debugsource-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: c1097c1bfd100f98e99bcd0b7e903e1a540928f25d11e4d2c595f0d58ea633be
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: ff4b9f170d1d46c512c6b2eed39192198f904ee6aa04fff852102fa7909d26c3
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: d3f8b7d0c26bbc55f612a21667eccbf846b92fb2885c926956894f9260ab06c3
gimp-libs-2.99.8-4.el9_2.5.i686.rpm SHA-256: bd62666543a6ef5c1dcf918223acecc6b254f0fe0f270a9ba87aadf7b8afc472
gimp-libs-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 41be0e61d801c2f0edaf47be1bdc35d0b128c8d3b7b9cfbf2962a6754c315283
gimp-libs-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: 32645e7b179caa147b4c5c7ef9304631a19d0caaf05aa5408387aae883b6f51b
gimp-libs-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 33a73e898719679674e9d794afde5c717bb4d92b87de6b7c2a524a98f156d937

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
gimp-2.99.8-4.el9_2.5.src.rpm SHA-256: 0f2f317be6a520271c162f294e8d5a7e3b8e31d61fcd9e7bbcb23df08ef8441d
ppc64le
gimp-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: 18deaec3a693d1763647f73901177b05f5cecbbc4b749a461df08e42820afd70
gimp-debuginfo-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: b57e00574bbb41bf66fce6503b8176fe687db11dafe51e661c937c967df3e621
gimp-debugsource-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: 9041aeede139cfe1be7aa26f7564af5c989398443fa4d8793bc084ba8885ec69
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: d4dd01be872430fef68368b6d155ca9e8f79e65a2130d17ee5dcc3a737c8a9e5
gimp-libs-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: cabea8f9aa71d86e3bd4727710d8c569c7b950ca421482900d96beb3495c8c9b
gimp-libs-debuginfo-2.99.8-4.el9_2.5.ppc64le.rpm SHA-256: 3cbb4094eaee8f7b08da1dc0494f8cd836941d2dfbd623642ac257d982287ce0

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
gimp-2.99.8-4.el9_2.5.src.rpm SHA-256: 0f2f317be6a520271c162f294e8d5a7e3b8e31d61fcd9e7bbcb23df08ef8441d
x86_64
gimp-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: e63e84a3bb206f5b1e86e13ae04f3d74d269b540da75c3a526176a72135c2056
gimp-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: fbc52aecad5bd7af996b8041c49c811eb4935717061c765f31b284c1305d085a
gimp-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 025caa65cd863fcf7af8b9183fff78de4caaf47b3abfae4af866b45b3bdf7a96
gimp-debugsource-2.99.8-4.el9_2.5.i686.rpm SHA-256: 6bc5297b4adba658a4818b787455dffd2ace80b86a522f85f92010fe416c437b
gimp-debugsource-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: c1097c1bfd100f98e99bcd0b7e903e1a540928f25d11e4d2c595f0d58ea633be
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: ff4b9f170d1d46c512c6b2eed39192198f904ee6aa04fff852102fa7909d26c3
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: d3f8b7d0c26bbc55f612a21667eccbf846b92fb2885c926956894f9260ab06c3
gimp-libs-2.99.8-4.el9_2.5.i686.rpm SHA-256: bd62666543a6ef5c1dcf918223acecc6b254f0fe0f270a9ba87aadf7b8afc472
gimp-libs-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 41be0e61d801c2f0edaf47be1bdc35d0b128c8d3b7b9cfbf2962a6754c315283
gimp-libs-debuginfo-2.99.8-4.el9_2.5.i686.rpm SHA-256: 32645e7b179caa147b4c5c7ef9304631a19d0caaf05aa5408387aae883b6f51b
gimp-libs-debuginfo-2.99.8-4.el9_2.5.x86_64.rpm SHA-256: 33a73e898719679674e9d794afde5c717bb4d92b87de6b7c2a524a98f156d937

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
gimp-2.99.8-4.el9_2.5.src.rpm SHA-256: 0f2f317be6a520271c162f294e8d5a7e3b8e31d61fcd9e7bbcb23df08ef8441d
aarch64
gimp-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: 1ba14318a37b8f714f72a1bbc16b9baf904814bc36461df6f75fc09ded772e9f
gimp-debuginfo-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: bfdc11ca297201d63fcf93d7f497617997b1fe55376d1db4f315c288c38c0b1a
gimp-debugsource-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: 5d7a34f5ea9be82665380b131d9b5c282ee29d7e6ee79b2f4e0f2a7e3d6e44fd
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: c0dcc81db11dbaadda359ad11e50089ece9ff51ee9241c376aede0376bf12ad0
gimp-libs-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: 2178e99b6b11cfbc5f92641c930227590c001981f1427cff74ea6be04bbb52e2
gimp-libs-debuginfo-2.99.8-4.el9_2.5.aarch64.rpm SHA-256: 7750499ca57fe976ee14e9404b3c01d098cadd0354f5f25dfac1b0f84b1f3d6a

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
gimp-2.99.8-4.el9_2.5.src.rpm SHA-256: 0f2f317be6a520271c162f294e8d5a7e3b8e31d61fcd9e7bbcb23df08ef8441d
s390x
gimp-2.99.8-4.el9_2.5.s390x.rpm SHA-256: f39dcf167e5958f0fe0c983c9c04ff932843cb47f378a7bb1f344c6eab9b8789
gimp-debuginfo-2.99.8-4.el9_2.5.s390x.rpm SHA-256: 59e50fd3accb5b4672f9e1ff032218bf8ef5c51229b4925e2fae66046ed2a02b
gimp-debugsource-2.99.8-4.el9_2.5.s390x.rpm SHA-256: 171d7dedb9ba7a46251b3e81156882250898b1bbc08456775752e2617055528a
gimp-devel-tools-debuginfo-2.99.8-4.el9_2.5.s390x.rpm SHA-256: 25fdbd3033235b0abe8c3d5e6ce0f3d95442999b26e191d445043cc87b2e25b9
gimp-libs-2.99.8-4.el9_2.5.s390x.rpm SHA-256: 341572cba19dc0cbe3a849ce81897d301bcef5447b0f23179979b2cc38a446d4
gimp-libs-debuginfo-2.99.8-4.el9_2.5.s390x.rpm SHA-256: 74bde1ae46a6522e40eac1c30e0c3afe2c851819202e45126da45acc7dc9fab1

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility