Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-38485 http://linux.oracle.com/errata/ELSA-2026-38485.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: gegl-0.2.0-40.el8_10.i686.rpm gegl-0.2.0-40.el8_10.x86_64.rpm aarch64: gegl-0.2.0-40.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/gegl-0.2.0-40.el8_10.src.rpm Related CVEs: CVE-2026-2050 Description of changes: [0.2.0-40] - Fix buffer overflow in rgbe_read_new_rle() (CVE-2026-2050) Resolves: RHEL-188260 _______________________________________________ El-errata mailing list
Important: gegl security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:38485", "synopsis": "Important: gegl security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for gegl.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "GEGL (Generic Graphics Library) is a graph-based image processing framework.\n\nSecurity Fix(es):\n\n* gimp: GIMP: Arbitrary code execution via heap-based buffer overflow in HDR file parsing (CVE-2026-2050)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2492593", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2492593", "description": ""}], "cves": [{"name": "CVE-2026-2050", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2050", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-131"}], "references": [], "publishedAt": "2026-07-14T06:00:51.502823Z", "rpms": {"Rocky Linux 8": {"nvras": ["gegl-0:0.2.0-40.el8_10.aarch64.rpm", "gegl-0:0.2.0-40.el8_10.i686.rpm", "gegl-0:0.2.0-40.el8_10.src.rpm", "gegl-0:0.2.0-40.el8_10.x86_64.rpm", "gegl-debuginfo-0:0.2.0-40.el8_10.aarch64.rpm", "gegl-debuginfo-0:0.2.0-40.el8_10.i686.rpm", "gegl-debuginfo-0:0.2.0-40.el8_10.x86_64.rpm", "gegl-debugsource-0:0.2.0-40.el8_10.aarch64.rpm", "gegl-debugsource-0:0.2.0-40.el8_10.i686.rpm", "gegl-debugsource-0:0.2.0-40.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Get the latest gegl security update for Rocky Linux 8 addressing a buffer overflow risk. Details inside.. Rocky Linux security, GEGL update, buffer overflow fix, securityoversight. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gegl Announcement ID: SUSE-SU-2026:1496-1 Release Date: 2026-04-20T16:14:44Z Rating: important References: * bsc#1259749 Cross-References: * CVE-2026-2049 CVSS scores: * CVE-2026-2049 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2049 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gegl fixes the following issues: * CVE-2026-2049: improper validation of the length of user-supplied data when parsing HDR files can lead to a heap buffer overflow (bsc#1259749). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1496=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libgegl-0_3-0-0.3.34-150000.3.9.1 * gegl-debuginfo-0.3.34-150000.3.9.1 * gegl-0_3-debuginfo-0.3.34-150000.3.9.1 * gegl-debugsource-0.3.34-150000.3.9.1 * gegl-0_3-0.3.34-150000.3.9.1 * libgegl-0_3-0-debuginfo-0.3.34-150000.3.9.1 * typelib-1_0-Gegl-0_3-0.3.34-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2049.html * https://bugzilla.suse.com/show_bug.cgi?id=1259749 . SUSE Security Update for gegl addressing important buffer overflow risk with CVE-2026-2049. Install recommended patches.. SUSE Linux, gegl, buffer overflow, security update, important patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gegl Announcement ID: SUSE-SU-2026:1479-1 Release Date: 2026-04-20T10:09:18Z Rating: important References: * bsc#1259749 Cross-References: * CVE-2026-2049 CVSS scores: * CVE-2026-2049 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2049 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gegl fixes the following issue: * CVE-2026-2049: improper validation of the length of user-supplied data when parsing HDR files can lead to a heap buffer overflow (bsc#1259749). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1479=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1479=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gegl-devel-0.2.0-15.14.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gegl-devel-0.2.0-15.14.2 ## References: * https://www.suse.com/security/cve/CVE-2026-2049.html * https://bugzilla.suse.com/show_bug.cgi?id=1259749 . SUSE update fixes important buffer overflow in GEGL, addressing CVE-2026-2049 with recommended installation methods.. SUSE update 2026, Buffer Overflow, GEGL Security Patch,CVE-2026-2049. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gegl Announcement ID: SUSE-SU-2026:1481-1 Release Date: 2026-04-20T10:09:56Z Rating: important References: * bsc#1259749 Cross-References: * CVE-2026-2049 CVSS scores: * CVE-2026-2049 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2049 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gegl fixes the following issue: * CVE-2026-2049: improper validation of the length of user-supplied data when parsing HDR files can lead to a heap buffer overflow (bsc#1259749). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1481=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1481=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1481=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * SUSE Linux Enterprise Workstation Extension 15 SP7(noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * gegl-doc-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * gegl-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (x86_64) * libgegl-0_4-0-32bit-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-32bit-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libgegl-0_4-0-64bit-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-64bit-0.4.46-150600.4.8.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * gegl-doc-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * gegl-0.4.46-150600.4.8.2 * SUSE Package Hub 15 15-SP7 (noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 ## References: * https://www.suse.com/security/cve/CVE-2026-2049.html * https://bugzilla.suse.com/show_bug.cgi?id=1259749 . Critical update for openSUSE addressing buffer overflow in gegl enhancing system security.. openSUSE security patch, gegl update, buffer overflow exploit, Linux security advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gegl Announcement ID: SUSE-SU-2026:1481-1 Release Date: 2026-04-20T10:09:56Z Rating: important References: * bsc#1259749 Cross-References: * CVE-2026-2049 CVSS scores: * CVE-2026-2049 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2049 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gegl fixes the following issue: * CVE-2026-2049: improper validation of the length of user-supplied data when parsing HDR files can lead to a heap buffer overflow (bsc#1259749). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1481=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1481=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1481=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * SUSE Linux Enterprise Workstation Extension 15 SP7(noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * gegl-doc-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * gegl-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (x86_64) * libgegl-0_4-0-32bit-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-32bit-0.4.46-150600.4.8.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libgegl-0_4-0-64bit-debuginfo-0.4.46-150600.4.8.2 * libgegl-0_4-0-64bit-0.4.46-150600.4.8.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * gegl-debuginfo-0.4.46-150600.4.8.2 * gegl-0_4-0.4.46-150600.4.8.2 * gegl-debugsource-0.4.46-150600.4.8.2 * gegl-0_4-debuginfo-0.4.46-150600.4.8.2 * gegl-doc-0.4.46-150600.4.8.2 * libgegl-0_4-0-0.4.46-150600.4.8.2 * libgegl-0_4-0-debuginfo-0.4.46-150600.4.8.2 * typelib-1_0-Gegl-0_4-0.4.46-150600.4.8.2 * gegl-devel-0.4.46-150600.4.8.2 * gegl-0.4.46-150600.4.8.2 * SUSE Package Hub 15 15-SP7 (noarch) * gegl-0_4-lang-0.4.46-150600.4.8.2 ## References: * https://www.suse.com/security/cve/CVE-2026-2049.html * https://bugzilla.suse.com/show_bug.cgi?id=1259749 . Solving the important heap overflow issue in gegl with SUSE 2026:1481-1 update to ensure system stability and security.. SUSE Update, Security Patch, Linux Application. . Severity: Important. LinuxSecurity.com Team
MGASA-2026-0047 - Updated gegl packages fix security vulnerabilities. MGASA-2026-0047 - Updated gegl packages fix security vulnerabilities Publication date: 23 Feb 2026 URL: https://advisories.mageia.org/MGASA-2026-0047.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-2049, CVE-2026-2050 Description: ZDI-CAN-28618: New Vulnerability Report at rgbe.c. (CVE-2026-2049) ZDI-CAN-28266: New Vulnerability Report at rgbe.c. (CVE-2026-2050) References: - https://bugs.mageia.org/show_bug.cgi?id=35147 - https://lists.debian.org/debian-security-announce/2026/msg00051.html - https://www.cve.org/CVERecord?id=CVE-2026-2049 - https://www.cve.org/CVERecord?id=CVE-2026-2050 SRPMS: - 9/core/gegl-0.4.42-1.1.mga9 . Mageia updated gegl packages address moderate security issues, protecting user data and application performance.. Mageia security advisories, gegl updates, application security issues, moderate severity vulnerabilities. . Severity: Important. LinuxSecurity.com Team
A heap-based buffer overflow was discovered in the RGBE/HDR parser of GEGL, a graph-based image processing library, which could result in denial of service or the execution of arbitrary code if malformed files are processed. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4487-1
Get the latest Linux and open source security news straight to your inbox.