vulnerability
Oracle Linux: CVE-2025-10921: ELSA-2025-21968: gimp security update (IMPORTANT) (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:M/Au:N/C:C/I:C/A:C) | Oct 29, 2025 | Nov 28, 2025 | Dec 4, 2025 |
Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Oct 29, 2025
Added
Nov 28, 2025
Modified
Dec 4, 2025
Description
A heap-based buffer-overflow in GIMP’s HDR (RGBE) file parsing (CVE-2025-10921 / ZDI-25-910) allows an attacker to execute arbitrary code when a user opens or is tricked into previewing a malicious HDR file. The flaw is caused by missing length validation before copying user-supplied HDR data into a heap buffer, enabling memory corruption and control of program flow.
Solutions
oracle-linux-upgrade-gimporacle-linux-upgrade-gimp-develoracle-linux-upgrade-gimp-devel-toolsoracle-linux-upgrade-gimp-libsoracle-linux-upgrade-pygobject2oracle-linux-upgrade-pygobject2-codegenoracle-linux-upgrade-pygobject2-develoracle-linux-upgrade-pygobject2-docoracle-linux-upgrade-pygtk2oracle-linux-upgrade-pygtk2-codegenoracle-linux-upgrade-pygtk2-develoracle-linux-upgrade-pygtk2-docoracle-linux-upgrade-python2-cairooracle-linux-upgrade-python2-cairo-devel
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.