Critical Vulnerabilities Found in openSUSE GIMP Software

Critical Vulnerabilities Found in openSUSE GIMP Software

First seen 24 Aug 2026, 16:53 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified in the GIMP software for openSUSE, specifically CVE-2026-59088 and CVE-2026-59090, both published on 2026-08-10. CVE-2026-59088 allows for denial of service via signed integer overflow in FLI file processing, while CVE-2026-59090 enables arbitrary code execution through an unsigned underflow in the PSD plugin. These vulnerabilities affect various versions of GIMP, including those in openSUSE Leap and Tumbleweed distributions. Users are advised to apply the patches provided in the advisory to mitigate these risks. The patches can be installed using SUSE's recommended methods, including YaST and zypper commands. The vulnerabilities pose a significant risk to users who have not yet updated their systems. As of now, the vulnerabilities have been disclosed and patched, but no active exploitation has been reported.

Key Points: • Two critical vulnerabilities in GIMP identified: CVE-2026-59088 and CVE-2026-59090. • CVE-2026-59088 allows denial of service; CVE-2026-59090 enables arbitrary code execution. • Users should apply patches immediately to secure their systems.

Timeline

2026-08-10
CVE-2026-59088 published
CVE-2026-59088 allows denial of service via signed integer overflow in FLI file processing.
Linuxsecurity
2026-08-10
CVE-2026-59090 published
CVE-2026-59090 enables arbitrary code execution in PSD plugin due to unsigned underflow.
Linuxsecurity
2026-08-24
Patch released for GIMP vulnerabilities
SUSE has released patches for both CVE-2026-59088 and CVE-2026-59090, urging users to update.
Linuxsecurity