TencentOS Server 3: gimp:2.8 (TSSA-2026:0972)

high Nessus Plugin ID 342619

Synopsis

The remote TencentOS Server 3 host is missing one or more security updates.

Description

The version of Tencent Linux installed on the remote TencentOS Server 3 host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the TSSA-2026:0972 advisory.

Package updates are available for TencentOS Server 3 that fix the following vulnerabilities:

CVE-2026-18301:
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability within the `read_channel_data` function during PSD (Photoshop Document) file parsing by enticing a user to open a specially crafted PSD file. This could lead to arbitrary code execution in the context of the current process.

CVE-2026-18303:
A flaw was found in GIMP. This vulnerability, a stack-based buffer overflow in the TIF file parsing component, allows a remote attacker to execute arbitrary code. User interaction is required, as the target must open a specially crafted malicious TIF file. The issue stems from insufficient validation of user- supplied data length before copying it to a buffer, leading to potential code execution in the context of the current process.

CVE-2026-18304:
A flaw was found in GIMP. This vulnerability allows a remote attacker to execute arbitrary code by tricking a user into opening a specially crafted TIF file. The issue arises from improper validation of user-supplied data during TIF file parsing, which can lead to an integer overflow before memory allocation. Successful exploitation could result in the attacker executing code in the context of the current process.

CVE-2026-18305:
A flaw was found in GIMP, an image manipulation program. This vulnerability allows a remote attacker to execute arbitrary code on an affected system. Exploitation requires user interaction, where the target must open a specially crafted TIF (Tagged Image File Format) file. The flaw occurs during TIF file parsing due to improper validation of user-supplied data, which can lead to an integer overflow and enable the attacker to run malicious code.

CVE-2026-18306:
A flaw was found in GIMP. This vulnerability, an integer overflow within the parsing of SGI (Silicon Graphics Image) files, allows a remote attacker to execute arbitrary code. Exploitation requires user interaction, where the target must open a specially crafted malicious SGI file. Successful exploitation could lead to the attacker executing code in the context of the current user's process.

CVE-2026-18307:
A flaw was found in GIMP. This heap-based buffer overflow vulnerability in the TIF file parsing component allows a remote attacker to execute arbitrary code. User interaction is required, as the target must open a specially crafted malicious TIF file. Successful exploitation can lead to arbitrary code execution in the context of the current process.

CVE-2026-58380:
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.

CVE-2026-66758:
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.

Tenable has extracted the preceding description block directly from the Tencent Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://mirrors.tencent.com/tlinux/errata/tssa-20260972.xml

Plugin Details

Severity: High

ID: 342619

File Name: tencentos_TSSA_2026_0972.nasl

Version: 1.1

Type: Local

Published: 9/3/2026

Updated: 9/3/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-58380

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:tencent:tencentos_server:3, p-cpe:/a:tencent:tencentos_server:gimp, p-cpe:/a:tencent:tencentos_server:pygobject2, p-cpe:/a:tencent:tencentos_server:pygtk2, p-cpe:/a:tencent:tencentos_server:python2-pycairo

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/etc/os-release, Host/TencentOS/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 4/30/2026

Reference Information

CVE: CVE-2026-18301, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-58380, CVE-2026-66758

IAVA: 2026-A-0402