Linuxsecurity
Critical Vulnerabilities Found in openSUSE GIMP Software
Article Content
Two critical vulnerabilities have been identified in the GIMP software for openSUSE, specifically CVE-2026-59088 and CVE-2026-59090, both published on 2026-08-10. CVE-2026-59088 allows for denial of service via signed integer overflow in FLI file processing, while CVE-2026-59090 enables arbitrary code execution through an unsigned underflow in the PSD plugin. These vulnerabilities affect various versions of GIMP, including those in openSUSE Leap and Tumbleweed distributions. Users are advised to apply the patches provided in the advisory to mitigate these risks. The patches can be installed using SUSE's recommended methods, including YaST and zypper commands. The vulnerabilities pose a significant risk to users who have not yet updated their systems. As of now, the vulnerabilities have been disclosed and patched, but no active exploitation has been reported.
Key Points: • Two critical vulnerabilities in GIMP identified: CVE-2026-59088 and CVE-2026-59090. • CVE-2026-59088 allows denial of service; CVE-2026-59090 enables arbitrary code execution. • Users should apply patches immediately to secure their systems.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.