vulnerability

Red Hat: CVE-2025-10920: gimp: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Oct 29, 2025
Added
Nov 25, 2025
Modified
Dec 2, 2025

Description

A remote code execution (RCE) vulnerability exists in GIMP due to improper bounds checking during the parsing of ICNS image files. When a user opens a specially crafted ICNS file, it can trigger an out-of-bounds write, allowing attackers to execute arbitrary code within the context of the GIMP process.

Solutions

redhat-upgrade-gimpredhat-upgrade-gimp-debuginforedhat-upgrade-gimp-debugsourceredhat-upgrade-gimp-develredhat-upgrade-gimp-devel-toolsredhat-upgrade-gimp-devel-tools-debuginforedhat-upgrade-gimp-libsredhat-upgrade-gimp-libs-debuginforedhat-upgrade-pygobject2redhat-upgrade-pygobject2-codegenredhat-upgrade-pygobject2-debuginforedhat-upgrade-pygobject2-debugsourceredhat-upgrade-pygobject2-develredhat-upgrade-pygobject2-docredhat-upgrade-pygtk2redhat-upgrade-pygtk2-codegenredhat-upgrade-pygtk2-debuginforedhat-upgrade-pygtk2-debugsourceredhat-upgrade-pygtk2-develredhat-upgrade-pygtk2-docredhat-upgrade-python2-cairoredhat-upgrade-python2-cairo-debuginforedhat-upgrade-python2-cairo-develredhat-upgrade-python2-pycairo-debugsource
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.