Multiple CVEs Discovered in GIMP for Rocky Linux and RHEL 9

Multiple CVEs Discovered in GIMP for Rocky Linux and RHEL 9

First seen 15 May 2026, 01:24 UTC Tenable 82% similarity 70.5

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities affecting GIMP in Rocky Linux 9 and RHEL 9 have been identified, with multiple CVEs published on March 26, 2026. The vulnerabilities include CVE-2026-4150, CVE-2026-4151, CVE-2026-4152, CVE-2026-4153, CVE-2026-4154, and CVE-2026-4887, all of which have available exploits. The vulnerabilities are categorized under various Common Weakness Enumerations (CWEs), including buffer errors and improper validation. The patch for Rocky Linux was published on May 14, 2026, while RHEL's patch was released on May 12, 2026. Administrators are advised to apply these patches promptly to mitigate potential exploitation. The vulnerabilities affect both distributions' GIMP packages, posing a risk to users and organizations relying on these systems. The current status indicates that exploits are available, heightening the urgency for remediation.

Key Points: • Multiple CVEs affecting GIMP in Rocky Linux 9 and RHEL 9 have been published. • Exploits for these vulnerabilities are available, increasing the risk of attacks. • Patches were released on May 12 and May 14, 2026; immediate application is recommended.

ThreatCluster AI

Timeline

2026-03-26
CVE-2026-4887 published
CVE-2026-4887 was published, marking the discovery of vulnerabilities in GIMP.
Tenable
2026-04-11
Multiple CVEs published
CVE-2026-4150, CVE-2026-4151, CVE-2026-4152, CVE-2026-4153, and CVE-2026-4154 were published.
Tenable
2026-04-11
CVE-2026-4154 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-11
CVE-2026-4151 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-11
CVE-2026-4150 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-11
CVE-2026-4152 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-11
CVE-2026-4153 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-12
RHEL 9 patch released
Red Hat released a patch for GIMP vulnerabilities in RHEL 9.
Tenable
2026-05-14
Rocky Linux 9 patch released
Rocky Linux released a patch for GIMP vulnerabilities, addressing multiple CVEs.
Tenable

Community

Browse all →

Tracked Entities in This Story