GNOME GIMP是GNOME基金会的一款图像编辑软件。 GNOME GIMP存在数字错误漏洞,该漏洞源于file-fits插件处理FITS图像文件时使用有符号32位整数计算内存分配大小,整数溢出导致堆缓冲区分配不足,cfitsio写入整行像素时触发堆缓冲区溢出,可能导致任意代码执行或拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GNOME | GIMP | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | 8100020260824165450.4c9c024f< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 2:3.0.4-4.el9_8.9< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 2:2.99.8-4.el9_6.20< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GNOME | GIMP | - | - |
|
| Red Hat | Red Hat Enterprise Linux 8 | 8100020260824165450.4c9c024f ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 2:3.0.4-4.el9_8.9 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 2:2.99.8-4.el9_6.20 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66759 | 7.1 HIGH | Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on cra |
| CVE-2026-66757 | 5.5 MEDIUM | Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi |
No comments yet