VDB
CVE-2025-15059
CVE-2025-15059
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Das "Gnu Image Manipulation Program" ist eine Open Source Software zum Bearbeiten von Bildern. Es ist auch Bestandteil vieler Linux Distributionen.
EPSS 0.76% · 52.6th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.76%
52.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Linux | |
| Red Hat | Red Hat Enterprise Linux | |
| Open Source | Open Source GIMP | |
| SUSE | SUSE Linux | |
| Ubuntu | Ubuntu Linux | |
| RESF | RESF Rocky Linux | |
| Debian | Debian Linux | |
| SUSE | SUSE openSUSE |
Timeline
- Dec 29, 2025 PoC Published
- Dec 29, 2025 CVE Published
- Jan 23, 2026 EPSS Score
- Jan 23, 2026 PoC Published
- Jan 26, 2026 EPSS Score
- Jan 29, 2026 EPSS Score
- Jan 29, 2026 PoC Published
- Jan 31, 2026 EPSS Score
- Feb 3, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
- Feb 9, 2026 EPSS Score
- Feb 12, 2026 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2931.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2931 advisory
- https://www.zerodayinitiative.com/advisories/ZDI-25-1196/ advisory
- https://gitlab.gnome.org/GNOME/gimp/-/commit/03575ac8cbb0ef3103b0a15d6598475088dcc15e advisory
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/37RO4TKU6KAK2H25OWZ6JI44VK52I437/ advisory
- https://lists.suse.com/pipermail/sle-security-updates/2026-January/023718.html advisory
- https://lists.debian.org/debian-security-announce/2026/msg00024.html advisory
- https://access.redhat.com/errata/RHSA-2026:2707 advisory
- https://linux.oracle.com/errata/ELSA-2026-2707.html advisory
- https://errata.build.resf.org/RLSA-2026:2707 advisory
- https://access.redhat.com/errata/RHSA-2026:2950 advisory
- https://access.redhat.com/errata/RHSA-2026:2953 advisory
- https://access.redhat.com/errata/RHSA-2026:2930 advisory
- https://lists.debian.org/debian-lts-announce/2026/02/msg00022.html advisory
- https://access.redhat.com/errata/RHSA-2026:2969 advisory
- https://ubuntu.com/security/notices/USN-8057-1 advisory