Skip to content
VulniPulse
Advisory severityHigh7.3Red Hat Linux

High [CVE-2025-48797] multiple heap buffer overflows in tga parser

This high-severity Red Hat Linux advisory covers CVE-2025-48797 affecting Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2025-48797 Source published Source updated

VulniPulse record published

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow.

Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-122.

Affected Red Hat products: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 6.

Will not fix / out of support: Red Hat Enterprise Linux 6.

Affected products named by the advisory: Red Hat package: gimp.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Fixed versions
  • gimp-2:2.8.22-1.el7_9.2
  • gimp:2.8-8100020250614205641.4c9c024f
  • gimp:2.8-8020020250618101631.c3a0935b
  • gimp:2.8-8040020250618100956.70584597
  • gimp:2.8-8060020250618100419.6af1eaf0
  • gimp:2.8-8080020250623120629.0621e4ee
  • gimp-2:2.99.8-4.el9_6.2
  • gimp-2:2.99.8-3.el9_0.1
  • gimp-2:2.99.8-4.el9_2.1
  • gimp-2:2.99.8-4.el9_4.1
  • RHSA-2025:9501
  • RHSA-2025:9165
  • RHSA-2025:9310
  • RHSA-2025:9308
  • RHSA-2025:9309
  • RHSA-2025:9569
  • RHSA-2025:9162
  • RHSA-2025:9315
  • RHSA-2025:9314
  • RHSA-2025:9316

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Currently no mitigation is available for this vulnerability.

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.