[Git][security-tracker-team/security-tracker][master] Add three new gimp issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 20:44:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ae1269ea by Salvatore Bonaccorso at 2026-09-14T21:43:32+02:00
Add three new gimp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -24,11 +24,20 @@ CVE-2026-90957 (Affected versions of MISP serve uploaded SVG images inline witho
 CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not reliably ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When proc ...)
-	TODO: check
+	- gimp <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
+	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2998
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
 CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
-	TODO: check
+	- gimp <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)
 CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted lighting ...)
-	TODO: check
+	- gimp <unfixed>
+	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
+	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
+	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
 CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary file read v ...)
 	TODO: check
 CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT tok ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ae1269ea8b47e118ddbc4a71f13ea280c6c1db01

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ae1269ea8b47e118ddbc4a71f13ea280c6c1db01
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/345f5ff5/attachment.htm>


More information about the debian-security-tracker-commits mailing list