[From nobody Sat Sep 12 12:53:06 2026
Received: (at submit) by bugs.debian.org; 29 Jul 2026 18:58:47 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.6 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FOURLA,
 FROMDEVELOPER,MD5_SHA1_SUM,SPF_HELO_NONE,SPF_PASS,
 USER_IN_DKIM_WELCOMELIST,XMAILER_REPORTBUG autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 25; hammy, 150; neutral, 69; spammy,
 0. spammytokens:
 hammytokens:0.000-+--Hx-spam-relays-external:sk:stravin,
 0.000-+--H*RT:sk:stravin, 0.000-+--Hx-spam-relays-external:311,
 0.000-+--H*RT:311, 0.000-+--H*RT:108
Return-path: &lt;carnil@debian.org&gt;
Received: from stravinsky.debian.org ([2001:41b8:202:deb::311:108]:39490)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;carnil@debian.org&gt;) id 1wp9UN-00ECMZ-1d
 for submit@bugs.debian.org; Wed, 29 Jul 2026 18:58:47 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; 
 s=smtpauto.stravinsky;
 h=X-Debian-User:Date:Message-ID:Subject:To:From:
 Content-Transfer-Encoding:MIME-Version:Content-Type:Reply-To:Cc:Content-ID:
 Content-Description:In-Reply-To:References;
 bh=wicYSH0fpNC17kTUWx5YnAHKttmtfS6OwDr4CobGuf4=; b=ojnog9KGvGVRgJXY/E43O57J8R
 DHDqNl2m7DUKUKPpo9uc3Tv1VQ9baOae0LrWfkqK/RAqR+fztVsnhvJn3jDGVwNxxAqvGe+QUTHeS
 Xm6KGQfrqYh/kSB9p48wKkT4zk1kfw1xPR7QPDXi7OaG4DicTi9+wmaOotnpUJJtSOFpy3IJHb5Fh
 sd+T8vj5owPLL0D3HYg+9wULqPsZlb4Yidytzwl8audCJWF8SVRduLfCqKLcprQzt5xzEwhNfDCgg
 3M8VgqYM22zaT4PCLneMYBFgg6zsIxGBPlejfnMyhdz+U5+0j/FWOAXsNi4jbfF6xP2kYhx/n4Tgq
 cHJnYrGQ==;
Received: from authenticated-user by stravinsky.debian.org with esmtpsa
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;carnil@debian.org&gt;) id 1wp9UL-008f6N-16
 for submit@bugs.debian.org; Wed, 29 Jul 2026 18:58:46 +0000
Received: from eldamar.lan (localhost [IPv6:::1])
 by eldamar.lan (Postfix) with ESMTP id 8A91DBE2EE7
 for &lt;submit@bugs.debian.org&gt;; Wed, 29 Jul 2026 20:58:44 +0200 (CEST)
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: gimp: CVE-2026-59089
Message-ID: &lt;178535152450.934601.7678943565181074340.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Wed, 29 Jul 2026 20:58:44 +0200
X-Debian-User: carnil
Delivered-To: submit@bugs.debian.org

Source: gimp
Version: 3.2.4-3
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerability was published for gimp.

CVE-2026-59089[0]:
| A flaw was found in GIMP. The PlayStation TIM loader, responsible
| for handling PlayStation image files, incorrectly calculates the
| size of the Color Look-Up Table (CLUT) due to an integer overflow.
| This occurs when multiplying num_colors and num_cluts, both 16-bit
| unsigned short integers, resulting in a value exceeding the maximum
| integer limit. An attacker could exploit this by providing a
| specially crafted image file, leading to undefined behavior and
| causing the GIMP plug-in to abort, effectively resulting in a denial
| of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59089
    https://www.cve.org/CVERecord?id=CVE-2026-59089
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/53cdb27fa2b1676d11e9677c9975b5ad7b61b2ee

Regards,
Salvatore
]