SUSE SLED15: gimp / gimp-devel / gimp-lang / gimp-plugin-aa / libgimp-2_0-0 / etc (SUSE-SU-2026:4409-1)

high Nessus Plugin ID 362542

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4409-1 advisory.

- CVE-2026-18301: Vulnerability Report at read_channel_data (bsc#1276230).
- CVE-2026-18302: TIF File Parsing Heap-based Buffer Overflow (bsc#1276231).
- CVE-2026-18303: TIF File Parsing Stack-based Buffer Overflow (bsc#1276232).
- CVE-2026-18304: TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276233).
- CVE-2026-18305: TIF File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276234).
- CVE-2026-18306: SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (bsc#1276235).
- CVE-2026-18307: File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (bsc#1276236).
- CVE-2026-90947: out-of-bounds write in the lighting effects plugin when processing a crafted preset file due to improper validation of the number of light sources (bsc#1280511).
- CVE-2026-90948: heap buffer overflow in the ICO loader when processing ICO files with embedded PNG images due to an integer overflow during calculation of buffer sizes (bsc#1280512).
- CVE-2026-92248: integer overflow when generating a thumbnail preview for a PSD file can lead to a heap buffer overflow (bsc#1280739).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1276230

https://bugzilla.suse.com/1276231

https://bugzilla.suse.com/1276232

https://bugzilla.suse.com/1276233

https://bugzilla.suse.com/1276234

https://bugzilla.suse.com/1276235

https://bugzilla.suse.com/1276236

https://bugzilla.suse.com/1280511

https://bugzilla.suse.com/1280512

https://bugzilla.suse.com/1280739

https://www.suse.com/security/cve/CVE-2026-18301

https://www.suse.com/security/cve/CVE-2026-18302

https://www.suse.com/security/cve/CVE-2026-18303

https://www.suse.com/security/cve/CVE-2026-18304

https://www.suse.com/security/cve/CVE-2026-18305

https://www.suse.com/security/cve/CVE-2026-18306

https://www.suse.com/security/cve/CVE-2026-18307

https://www.suse.com/security/cve/CVE-2026-90947

https://www.suse.com/security/cve/CVE-2026-90948

https://www.suse.com/security/cve/CVE-2026-92248

http://www.nessus.org/u?1ddefbff

Plugin Details

Severity: High

ID: 362542

File Name: suse_SU-2026-4409-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.35

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-92248

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:gimp-devel, p-cpe:/a:novell:suse_linux:gimp-lang, p-cpe:/a:novell:suse_linux:gimp-plugin-aa, p-cpe:/a:novell:suse_linux:gimp, p-cpe:/a:novell:suse_linux:libgimp-2_0-0, p-cpe:/a:novell:suse_linux:libgimpui-2_0-0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/1/2026

Vulnerability Publication Date: 4/30/2026

Reference Information

CVE: CVE-2026-18301, CVE-2026-18302, CVE-2026-18303, CVE-2026-18304, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-90947, CVE-2026-90948, CVE-2026-92248

IAVA: 2026-A-0402-S, 2026-A-1032

SuSE: SUSE-SU-2026:4409-1