[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-90947/gimp
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Sep 20 12:39:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b6f836f6 by Salvatore Bonaccorso at 2026-09-20T13:38:19+02:00
Update status for CVE-2026-90947/gimp
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11092,10 +11092,11 @@ CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an I
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)
CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted lighting ...)
- - gimp <unfixed> (bug #1148481)
+ - gimp 3.2.6-1 (bug #1148481)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
+ NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2360b2edd14b2436fc82017854027e916598439b (GIMP_3_2_6)
CVE-2026-90946 (DeepWiki-Open through commit d92819a contains an arbitrary file read v ...)
NOT-FOR-US: DeepWiki-Open
CVE-2026-90945 (Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT tok ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6f836f690a519e2e3c647406b4352cb86c9d5b0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b6f836f690a519e2e3c647406b4352cb86c9d5b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/477a2211/attachment.htm>
More information about the debian-security-tracker-commits
mailing list