Amazon Linux 2 Security Advisory: ALAS2GIMP-2026-011
Advisory Released Date: 2026-03-06
Advisory Updated Date: 2026-03-06
GIMP: PSD loader: heap-buffer-overflow in fread_pascal_string() (no null terminator) (CVE-2026-2239)
An integer overflow vulnerability has been identified in the PSP (Paint Shop Pro) file parser of GIMP. The issue occurs in the read_creator_block() function, where the Creator metadata block is processed. Specifically, a 32-bit length value read from the file is used directly for memory allocation without proper validation. (CVE-2026-2271)
GIMP: ICO import integer overflow bypass leads to heap buffer overflow (CVE-2026-2272)
Affected Packages:
gimp
Note:
This advisory is applicable to Amazon Linux 2 - Gimp Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update gimp or yum update --advisory ALAS2GIMP-2026-011 to update your system.
src:
gimp-2.8.22-1.amzn2.0.11.src
x86_64:
gimp-2.8.22-1.amzn2.0.11.x86_64
gimp-libs-2.8.22-1.amzn2.0.11.x86_64
gimp-devel-2.8.22-1.amzn2.0.11.x86_64
gimp-devel-tools-2.8.22-1.amzn2.0.11.x86_64
gimp-debuginfo-2.8.22-1.amzn2.0.11.x86_64