[From nobody Sat Sep 12 12:53:19 2026
Received: (at submit) by bugs.debian.org; 30 Aug 2026 08:52:09 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-111.0 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FOURLA,
 FROMDEVELOPER,SPF_HELO_NONE,SPF_PASS,USER_IN_DKIM_WELCOMELIST,
 XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 19; hammy, 150; neutral, 62; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;carnil@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:37432)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;carnil@debian.org&gt;) id 1x0bGr-003N7r-0b
 for submit@bugs.debian.org; Sun, 30 Aug 2026 08:52:09 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Date:Message-ID:Subject:To:From:
 Content-Transfer-Encoding:MIME-Version:Content-Type:Reply-To:Cc:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=3iB99DVawznrlrBEoVFqyCM4Hb+OAzE8/aF0e+VfCpc=; b=Q8I9/PVtwp4D4c43m/Ad3NcW8x
 hor90RrIyvKk2LHFXKFArgPzUgyOKDI124B5DPf4pqZ5qroU4Uzu0nPUHkxXGCFToAzQmqBQE0qHt
 t3HyxR+a/H8ZHP2SeZQKg59oZtEgiAofsrQxbNnVoHmV7mOA/B+0TURrFWwuYxFsPrqa+ZErDL0lD
 ndlOCVGNKZ9oR2hduNPf8HkGK5LYf53FyMnPJiaV3prds0OuBx19QNp7Qati6hp37MdbqpsNooGOs
 s9JAUqhLx2zPzpiQqRn8+Mh5zLzZeMRO9UrB6Zu0ZOLiRMolbKTlExOOrWhZUns80dODKn6n7kSMZ
 gsEuizTA==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;carnil@debian.org&gt;) id 1x0bGo-000cem-34
 for submit@bugs.debian.org; Sun, 30 Aug 2026 08:52:07 +0000
Received: from eldamar.lan (localhost [IPv6:::1])
 by eldamar.lan (Postfix) with ESMTP id 9F5C0BE2DE0
 for &lt;submit@bugs.debian.org&gt;; Sun, 30 Aug 2026 10:52:06 +0200 (CEST)
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: gimp: CVE-2026-82343
Message-ID: &lt;178807992664.810202.11915760831291416460.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Sun, 30 Aug 2026 10:52:06 +0200
X-Debian-User: carnil
Delivered-To: submit@bugs.debian.org

Source: gimp
Version: 3.2.4-3
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerability was published for gimp.

CVE-2026-82343[0]:
| A flaw was found in the file-psd plugin in GIMP. When processing a
| specially crafted PSD image file, the plugin does not properly
| validate the channel-count parameter. This incorrect validation
| leads to improper memory bounds checking, resulting in both a heap
| out-of-bounds read and a stack out-of-bounds access. This issue can
| result in an application crash, leading to a denial of service or a
| limited information disclosure of memory contents.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-82343
    https://www.cve.org/CVERecord?id=CVE-2026-82343
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
]