[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 21 22:35:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
670ba4aa by Moritz Muehlenhoff at 2026-08-21T23:35:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17987,8 +17987,12 @@ CVE-2026-59112 (Improper verification of cryptographic signature and Improper Ch
 	NOT-FOR-US: Estonian Information System Authority (RIA)
 CVE-2026-59091 (A flaw was found in GIMP's file format plugins, including those for PS ...)
 	- gimp <unfixed> (bug #1144520)
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
+	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16510
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/eb91d3b793fbe0766520a3510d9396fbbed916f7
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/901d1cd9d9680927e76001ad13411fe0df922300 (GIMP_3_1_4)
 CVE-2026-59090 (A flaw was found in GIMP's PSD file format plugin. This vulnerability, ...)
 	- gimp <unfixed> (bug #1144526)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16509
@@ -30173,6 +30177,7 @@ CVE-2026-66758 (A flaw was found in the file-fits plugin in GIMP. When processin
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9
 CVE-2026-66757 (A flaw was found in the file-sgi plugin in GIMP. When processing an RL ...)
 	- gimp <unfixed> (bug #1142990)
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2884
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/adb89f0f2c086240fc49f6e2c946d89e10b66a70
@@ -49015,20 +49020,36 @@ CVE-2026-58383
 	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd (GIMP_3_1_2)
 CVE-2026-58385
 	- gimp 3.2.4-1
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
+	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16221
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/496e9d4f507230c3bbe1c4fe4e1e9c785641d55b (GIMP_3_2_4)
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/96a9000169a11742cad88b6f945c12766cbf3f42 (GIMP_3_2_0)
 CVE-2026-58386
 	- gimp 3.2.4-1
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
+	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16222
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/88a0a895da560d2e684b13eb8f532a314c01a504 (GIMP_3_2_4)
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/d5cdeb96e868308fa529916edbf3034981a664f3 (GIMP_3_1_2)
 CVE-2026-58387
 	- gimp 3.2.4-1
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
+	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16230
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c1263f391fd685e41c09cd9b7555532c25e697c3 (GIMP_3_2_4)
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/494f3a1452b6b4c4d61e9d3483b528c98821fb93 (GIMP_3_1_4)
 CVE-2026-58388
 	- gimp 3.2.4-1
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
+	[bullseye] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16231
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/c1263f391fd685e41c09cd9b7555532c25e697c3 (GIMP_3_2_4)
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/494f3a1452b6b4c4d61e9d3483b528c98821fb93 (GIMP_3_1_4)
 CVE-2026-14454 (Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry co ...)
 	- libimager-perl 1.033+dfsg-1 (bug #1141959)
 	[trixie] - libimager-perl <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/670ba4aa8da7525e6ef1fcc3374a63cf5e1cfb0d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/670ba4aa8da7525e6ef1fcc3374a63cf5e1cfb0d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/ff526eb4/attachment.htm>


More information about the debian-security-tracker-commits mailing list