Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    OESA-2026-1710 (CVE-2026-2046)

    Vulnerability from osv_openeuler – Published: 2026-03-27 11:10 – Updated: 2026-08-06 11:10 – Source website
    VLAI
    Summary
    gimp security update
    Details

    The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.

    Security Fix(es):

    A vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)

    (CVE-2026-4152)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "gimp-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-devel-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-libs-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403.aarch64.rpm",
              "gimp-vala-3.0.2-11.oe2403.aarch64.rpm"
            ],
            "src": [
              "gimp-3.0.2-11.oe2403.src.rpm"
            ],
            "x86_64": [
              "gimp-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-devel-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-libs-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403.x86_64.rpm",
              "gimp-vala-3.0.2-11.oe2403.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS",
            "name": "gimp",
            "purl": "pkg:rpm/openEuler/gimp\u0026distro=openEuler-24.03-LTS"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.0.2-11.oe2403"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.\r\n\r\nSecurity Fix(es):\n\nA vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)\n\n(CVE-2026-4152)",
      "id": "OESA-2026-1710",
      "modified": "2026-08-06T11:10:44Z",
      "published": "2026-03-27T11:10:44Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1710"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2046"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4152"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gimp security update",
      "upstream": [
        "CVE-2026-2046",
        "CVE-2026-4152"
      ]
    }

    OESA-2026-1711 (CVE-2026-2046)

    Vulnerability from osv_openeuler – Published: 2026-03-27 11:10 – Updated: 2026-08-06 11:10 – Source website
    VLAI
    Summary
    gimp security update
    Details

    The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.

    Security Fix(es):

    A vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)

    (CVE-2026-4152)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "gimp-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp1.aarch64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp1.aarch64.rpm"
            ],
            "src": [
              "gimp-3.0.2-11.oe2403sp1.src.rpm"
            ],
            "x86_64": [
              "gimp-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp1.x86_64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp1.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP1",
            "name": "gimp",
            "purl": "pkg:rpm/openEuler/gimp\u0026distro=openEuler-24.03-LTS-SP1"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.0.2-11.oe2403sp1"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.\r\n\r\nSecurity Fix(es):\n\nA vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)\n\n(CVE-2026-4152)",
      "id": "OESA-2026-1711",
      "modified": "2026-08-06T11:10:44Z",
      "published": "2026-03-27T11:10:44Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1711"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2046"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4152"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gimp security update",
      "upstream": [
        "CVE-2026-2046",
        "CVE-2026-4152"
      ]
    }

    OESA-2026-1712 (CVE-2026-2046)

    Vulnerability from osv_openeuler – Published: 2026-03-27 11:10 – Updated: 2026-08-06 11:10 – Source website
    VLAI
    Summary
    gimp security update
    Details

    The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.

    Security Fix(es):

    A vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)

    (CVE-2026-4152)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "gimp-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp2.aarch64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp2.aarch64.rpm"
            ],
            "src": [
              "gimp-3.0.2-11.oe2403sp2.src.rpm"
            ],
            "x86_64": [
              "gimp-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp2.x86_64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp2.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP2",
            "name": "gimp",
            "purl": "pkg:rpm/openEuler/gimp\u0026distro=openEuler-24.03-LTS-SP2"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.0.2-11.oe2403sp2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.\r\n\r\nSecurity Fix(es):\n\nA vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)\n\n(CVE-2026-4152)",
      "id": "OESA-2026-1712",
      "modified": "2026-08-06T11:10:44Z",
      "published": "2026-03-27T11:10:44Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1712"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2046"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4152"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gimp security update",
      "upstream": [
        "CVE-2026-2046",
        "CVE-2026-4152"
      ]
    }

    OESA-2026-1713 (CVE-2026-2046)

    Vulnerability from osv_openeuler – Published: 2026-03-27 11:10 – Updated: 2026-08-06 11:10 – Source website
    VLAI
    Summary
    gimp security update
    Details

    The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.

    Security Fix(es):

    A vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)

    (CVE-2026-4152)


    {
      "affected": [
        {
          "ecosystem_specific": {
            "aarch64": [
              "gimp-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp3.aarch64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp3.aarch64.rpm"
            ],
            "src": [
              "gimp-3.0.2-11.oe2403sp3.src.rpm"
            ],
            "x86_64": [
              "gimp-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-debuginfo-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-debugsource-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-devel-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-extension-goat-excercises-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-libs-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-plugin-aa-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-plugin-python3-3.0.2-11.oe2403sp3.x86_64.rpm",
              "gimp-vala-3.0.2-11.oe2403sp3.x86_64.rpm"
            ]
          },
          "package": {
            "ecosystem": "openEuler:24.03-LTS-SP3",
            "name": "gimp",
            "purl": "pkg:rpm/openEuler/gimp\u0026distro=openEuler-24.03-LTS-SP3"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.0.2-11.oe2403sp3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "database_specific": {
        "severity": "High"
      },
      "details": "The GIMP is an image composition and editing program, which can be used for creating logos and other graphics for Web pages. The GIMP offers many tools and filters, and provides a large image manipulation toolbox, including channel operations and layers, effects, subpixel imaging and antialiasing, and conversions, together with multilevel undo. The GIMP offers a scripting facility, but many of the included scripts rely on fonts that we cannot distribute.\r\n\r\nSecurity Fix(es):\n\nA vulnerability classified as critical was found in GIMP (Image Processing Software) (version now known).The CWE definition for the vulnerability is CWE-122. A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().As an impact it is known to affect confidentiality, integrity, and availability.Applying a patch is able to eliminate this problem.(CVE-2026-2046)\n\n(CVE-2026-4152)",
      "id": "OESA-2026-1713",
      "modified": "2026-08-06T11:10:44Z",
      "published": "2026-03-27T11:10:44Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1713"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2046"
        },
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4152"
        }
      ],
      "schema_version": "1.7.2",
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "gimp security update",
      "upstream": [
        "CVE-2026-2046",
        "CVE-2026-4152"
      ]
    }

    UBUNTU-CVE-2026-2046 (CVE-2026-2046)

    Vulnerability from osv_ubuntu – Published: 2026-03-19 00:00 – Updated: 2026-08-10 12:25 – Source website
    VLAI

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "2.8.16-1ubuntu1.1+esm3"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "2.8.16-1ubuntu1.1+esm3"
              },
              {
                "binary_name": "libgimp2.0",
                "binary_version": "2.8.16-1ubuntu1.1+esm3"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:16.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@2.8.16-1ubuntu1.1+esm3?arch=source\u0026distro=esm-apps/xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.8.14-1ubuntu2",
            "2.8.14-1.2ubuntu1",
            "2.8.16-1ubuntu1",
            "2.8.16-1ubuntu1.1",
            "2.8.16-1ubuntu1.1+esm1",
            "2.8.16-1ubuntu1.1+esm2",
            "2.8.16-1ubuntu1.1+esm3"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "2.8.22-1ubuntu0.1~esm3"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "2.8.22-1ubuntu0.1~esm3"
              },
              {
                "binary_name": "libgimp2.0",
                "binary_version": "2.8.22-1ubuntu0.1~esm3"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:18.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@2.8.22-1ubuntu0.1~esm3?arch=source\u0026distro=esm-apps/bionic"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.8.20-1",
            "2.8.20-1.1",
            "2.8.20-2",
            "2.8.22-1",
            "2.8.22-1ubuntu0.1~esm1",
            "2.8.22-1ubuntu0.1~esm2",
            "2.8.22-1ubuntu0.1~esm3"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "2.10.18-1ubuntu0.1+esm3"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "2.10.18-1ubuntu0.1+esm3"
              },
              {
                "binary_name": "libgimp2.0",
                "binary_version": "2.10.18-1ubuntu0.1+esm3"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:20.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@2.10.18-1ubuntu0.1+esm3?arch=source\u0026distro=esm-apps/focal"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.10.8-2",
            "2.10.14-2",
            "2.10.14-2build1",
            "2.10.14-2ubuntu1",
            "2.10.14-3",
            "2.10.18-1",
            "2.10.18-1ubuntu0.1",
            "2.10.18-1ubuntu0.1+esm1",
            "2.10.18-1ubuntu0.1+esm2",
            "2.10.18-1ubuntu0.1+esm3"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "2.10.30-1ubuntu0.1+esm3"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "2.10.30-1ubuntu0.1+esm3"
              },
              {
                "binary_name": "libgimp2.0",
                "binary_version": "2.10.30-1ubuntu0.1+esm3"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:22.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@2.10.30-1ubuntu0.1+esm3?arch=source\u0026distro=esm-apps/jammy"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.10.24-2",
            "2.10.28-1",
            "2.10.30-1",
            "2.10.30-1build1",
            "2.10.30-1ubuntu0.1",
            "2.10.30-1ubuntu0.1+esm1",
            "2.10.30-1ubuntu0.1+esm2",
            "2.10.30-1ubuntu0.1+esm3"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "2.10.36-3ubuntu0.24.04.1+esm3"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "2.10.36-3ubuntu0.24.04.1+esm3"
              },
              {
                "binary_name": "libgimp2.0t64",
                "binary_version": "2.10.36-3ubuntu0.24.04.1+esm3"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:Pro:24.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@2.10.36-3ubuntu0.24.04.1+esm3?arch=source\u0026distro=esm-apps/noble"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2.10.34-1",
            "2.10.36-1",
            "2.10.36-2",
            "2.10.36-3build2",
            "2.10.36-3build3",
            "2.10.36-3ubuntu0.24.04.1",
            "2.10.36-3ubuntu0.24.04.1+esm1",
            "2.10.36-3ubuntu0.24.04.1+esm2",
            "2.10.36-3ubuntu0.24.04.1+esm3"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "3.0.4-6.1"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "3.0.4-6.1"
              },
              {
                "binary_name": "gir1.2-gimp-3.0",
                "binary_version": "3.0.4-6.1"
              },
              {
                "binary_name": "libgimp-3.0-0",
                "binary_version": "3.0.4-6.1"
              },
              {
                "binary_name": "libgimp-3.0-bin",
                "binary_version": "3.0.4-6.1"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:25.10",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@3.0.4-6.1?arch=source\u0026distro=questing"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.0.2-1",
            "3.0.2-2",
            "3.0.2-3",
            "3.0.2-3.1",
            "3.0.4-1",
            "3.0.4-2",
            "3.0.4-3",
            "3.0.4-5",
            "3.0.4-6",
            "3.0.4-6.1"
          ]
        },
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gimp",
                "binary_version": "3.2.2-1ubuntu0.26.04.1"
              },
              {
                "binary_name": "gimp-data",
                "binary_version": "3.2.2-1ubuntu0.26.04.1"
              },
              {
                "binary_name": "gir1.2-gimp-3.0",
                "binary_version": "3.2.2-1ubuntu0.26.04.1"
              },
              {
                "binary_name": "libgimp-3.0-0",
                "binary_version": "3.2.2-1ubuntu0.26.04.1"
              },
              {
                "binary_name": "libgimp-3.0-bin",
                "binary_version": "3.2.2-1ubuntu0.26.04.1"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:26.04:LTS",
            "name": "gimp",
            "purl": "pkg:deb/ubuntu/gimp@3.2.2-1ubuntu0.26.04.1?arch=source\u0026distro=resolute"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "3.0.4-6.1",
            "3.0.4-6.2",
            "3.0.6-1",
            "3.2.0~RC2-2",
            "3.2.0~RC2-3",
            "3.2.0~RC2-3.1",
            "3.2.0~RC2-3.2",
            "3.2.0~RC2-3.3",
            "3.2.0~RC3-1",
            "3.2.0-1",
            "3.2.2-1",
            "3.2.2-1ubuntu0.26.04.1"
          ]
        }
      ],
      "aliases": [],
      "details": "[Unknown description]",
      "id": "UBUNTU-CVE-2026-2046",
      "modified": "2026-08-10T12:25:07Z",
      "published": "2026-03-19T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2026-2046"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-2046"
        },
        {
          "type": "REPORT",
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/commit/b4d41182dde4a1f98431b4d5b749a5a18bed0ab3"
        },
        {
          "type": "REPORT",
          "url": "https://gitlab.gnome.org/GNOME/gimp/-/issues/15289"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "medium",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2026-2046"
      ]
    }

    WID-SEC-W-2026-0750

    Vulnerability from csaf_certbund - Published: 2026-03-16 23:00 - Updated: 2026-06-10 22:00
    Summary
    GIMP: Mehrere Schwachstellen ermöglichen Codeausführung
    Severity
    Mittel
    Scope
    2 vulnerabilities in this advisory, including CVE-2026-2046.
    CVE-2026-2046
    Known affected: 2 products
    Open the full advisory