ELSA-2026-17533

ELSA-2026-17533 - gimp:2.8 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-05-15

Description


gimp
[2:2.8.22-26.6]
- fix CVE-2026-4150
- fix CVE-2026-4153
- fix CVE-2026-4154
- fix CVE-2026-4887

[2:2.8.22-26.5]
- fix CVE-2026-0797
- fix CVE-2026-2044
- fix CVE-2026-2045
- fix CVE-2026-2048

[2:2.8.22-26.4]
- fix CVE-2025-14422

[2:2.8.22-26.3]
- fix CVE-2025-10920
- fix CVE-2025-10921
- fix CVE-2025-10922
- fix CVE-2025-10923
- fix CVE-2025-10924
- fix CVE-2025-10925
- fix CVE-2025-10934

[2:2.8.22-26.2]
- fix CVE-2025-5473 (RHEL-95696)

[2:2.8.22-26.1]
- fix CVE-2025-48797 (RHEL-93503)
- fix CVE-2025-48798 (RHEL-93506)

[2:2.28.22-26]
- bump spec

[2:2.8.22-25]
- fix CVE-2023-44442
- fix CVE-2023-44444
- disable gimp-2.8.22-python-path.patch required for flatpak
- partially cherry-pick from upstream commit 2987f012 to fix fclose leak
Resolves: RHEL-17048 RHEL-17060

[2:2.8.22-24]
- fallback to RPM gegl

[2:2.8.22-23]
- enforce gegl04

pygobject2
[2.28.7-5]
- bump spec to fix NVR

[2.28.7-4]
- update python macro to python2

[2.28.7-3]
- Add MIT license

[2.28.7-2.1]
- Fix python shebangs (#1580854)

[2.28.7-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.28.7-1]
- Update to 2.28.7

[2.28.6-19]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

[2.28.6-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[2.28.6-17]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

[2.28.6-16]
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages

pygtk2
[2.24.0-25]
- Fix shebang mangling for _prefix=app (#1907579)
- disable numpy for flatpak (#1907579)

[2.24.0-24]
- remove libglade dependency and sub-package (#1622134)

[2.24.0-23.1]
- fix python2 regex in sed command

[2.24.0-23]
- resotre doc sub package

[2.24.0-22]
- fix python2 macros

[2.24.0-21.1]
- Fix python shebangs (#1580855)

[2.24.0-21]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.24.0-20]
- Try again to fix shebangs

[2.24.0-19]
- Fix shebangs

[2.24.0-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

python2-pycairo
[1.16.3-7]
- bump spec for NVR fix

[1.16.3-6]
- Rename pycairo to python2-pycairo (RCM-39388)

[1.16.3-5]
- Add python3 packages (RCM-39388)
- remove python3-test due its missing in build root

[1.16.3-4]
- Setup python2 stream branch for python2 binding of cairo library

[1.16.3-3]
- Remove the python2 subpackages
https://bugzilla.redhat.com/show_bug.cgi?id=1590820

[1.16.3-2]
- Allow Python 2 for build
See: https://hurl.corp.redhat.com/rhel8-py2

- Skip tests on Python 2 (python2-pytest is being removed)

[1.16.3-1]
- Update to 1.16.3

[1.16.1-1]
- Update to 1.16.1

[1.16.0-1]
- Update to 1.16.0

[1.15.6-1]
- Update to 1.15.6


Related CVEs


CVE-2026-4150
CVE-2026-4153
CVE-2026-4154
CVE-2026-4887

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.src.rpm7f32508b1b9d57eebbf38f791db8e9d49a39e04df198a61577d799bd11da786c-ol8_aarch64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpmf2b6af9a436a0ac325d7ed2dc45c5c7d2b479753d5bcc456fc952e48cd198892-ol8_aarch64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpmf039bb4150fe124bdb1b2ad25a51fbccdb61b56e76e2eceb04626322eb3bf1b0-ol8_aarch64_appstream
python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm546c0b737a1ad1280ea1fa8b46867e48a644d1b38f71b1f44c0597141d220365-ol8_aarch64_appstream
gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpmd86727689e3b8dfd99e0fd949818f7afabfecfb40c473e5d1d759eb2e6755694-ol8_aarch64_appstream
gimp-devel-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm8dec5dcb64562531813a4aa6693560ee4e5f257603702762ddae28a099e83d2d-ol8_aarch64_appstream
gimp-devel-tools-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm2fec7be998bbdbaa62bbb0c9710275697ffba81a7d1aef670c66e5ae985f5878-ol8_aarch64_appstream
gimp-libs-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.aarch64.rpm31b6d60b6c3e3484ecba2d5849f5845400f1972805775e764542b07702998b3d-ol8_aarch64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm697745da92fdda68afc4a28ebab9bb0108a616c18f5179f318a6aa1872a6e866-ol8_aarch64_appstream
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm7ba269d3b647be8cf33097fc7a82228e5073485dc794524f756849b961ca1cf6-ol8_aarch64_appstream
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm2da7da07bc9349133b9c3ffb0e74131db72024531aa526b8a3e8cec89b62ca75-ol8_aarch64_appstream
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm2f593b1f9ec7099e8c71b89d0e680fdf6aaa38675d8ae8843ed372df40906ca6-ol8_aarch64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpmebcba5b9fd0a569644e692d18ee447b11aefdc546dcee720c2ea3cbdc4f4b890-ol8_aarch64_appstream
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm6804209be9d482549468d30e62e8fec965696076554db653e28f07504e107fbd-ol8_aarch64_appstream
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm63f1c4141df33d4f13da5c4b6737af826b7f837ac3c52da55e7522ba1cbdc31f-ol8_aarch64_appstream
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm08de36761520a45a1ff60fbd54e511ebc7e03e1abfa95c8938c1b3cda33009e0-ol8_aarch64_appstream
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpmb3525b5ea4f9c6c2d1fe567bed6099962fb2dfd29bede936970a073d3c07072d-ol8_aarch64_appstream
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpmf5184a0c70a5101af09574f608dc5d57525d954a4c7e0068dfb0eee4cb6a28b7-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.src.rpm7f32508b1b9d57eebbf38f791db8e9d49a39e04df198a61577d799bd11da786c-ol8_x86_64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpmf2b6af9a436a0ac325d7ed2dc45c5c7d2b479753d5bcc456fc952e48cd198892-ol8_x86_64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpmf039bb4150fe124bdb1b2ad25a51fbccdb61b56e76e2eceb04626322eb3bf1b0-ol8_x86_64_appstream
python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm546c0b737a1ad1280ea1fa8b46867e48a644d1b38f71b1f44c0597141d220365-ol8_x86_64_appstream
gimp-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpme696d21004360a0ca02eaa8c55405f809ac06057154b0b9ac9e56cfdec85303d-ol8_x86_64_appstream
gimp-devel-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpm143a93c8784d1c9a2c46e07bc727756af2539339833456f033053ba6940b395a-ol8_x86_64_appstream
gimp-devel-tools-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpmf053883b7c929bb10ed0616353b48f3e34db3472321f77217c74f576858f79b2-ol8_x86_64_appstream
gimp-libs-2.8.22-26.module+el8.10.0+90890+b83bdeeb.6.x86_64.rpmd9be4e17332e1cba481da9c8dd603172925d6b74e2e8c3991b0688d54fd5d9b8-ol8_x86_64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm57ae4e3ea05328596812a517c996ea4c9adda0c7f2e28bcb4d25ca6c0020a5ad-ol8_x86_64_appstream
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm8d5aa2c450cd2cb6037dfd721fd424e6a64f83b3b0febd08941dd447aa4536fc-ol8_x86_64_appstream
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm3876c60435a4a075833ef14beea16bb74dae21a98c36e9e8174969c6ceb62aba-ol8_x86_64_appstream
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm32032c9385ad1f1d6551945f5d722197f6eaf56050a9fb452b675ca5ef6570eb-ol8_x86_64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm3231b036ebfb1ddcfee4cc0a0dfb016c3d08200decd7bf96fe65c2d3853a9c55-ol8_x86_64_appstream
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpmf54b672a43d5be06fbe020c956a9041a7d9cb7ccda3d55ee88aefdaeef4a0d47-ol8_x86_64_appstream
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpmce2349c3fc91801f567947f237a419c664226e9230a0ba204cb15d57c0b4f711-ol8_x86_64_appstream
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm08de36761520a45a1ff60fbd54e511ebc7e03e1abfa95c8938c1b3cda33009e0-ol8_x86_64_appstream
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpmaffb725f331e18fc5cae82b37832af8e4d99ddb1d4db6fa6aebc9e966bb84da5-ol8_x86_64_appstream
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm7b80515f9bbff35c9e70bb6d7b53409aacbdcf8b830641a1cb6d6acb96e3b755-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete