[Git][security-tracker-team/security-tracker][master] gimp DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 18:53:59 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0b3ecfe9 by Moritz Mühlenhoff at 2026-09-20T19:53:36+02:00
gimp DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -28579,7 +28579,6 @@ CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a (GIMP_3_2_6)
 CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
 	- gimp 3.2.6-1 (bug #1146133)
-	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e (GIMP_3_2_6)
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
@@ -34931,12 +34930,10 @@ CVE-2026-78541 (A stored OS command injection vulnerability exists in the parent
 	NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...)
 	- gimp 3.2.6-1 (bug #1145874)
-	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8 (GIMP_3_2_6)
 CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit buil ...)
 	- gimp 3.2.6-1 (bug #1145875)
-	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16578
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d (GIMP_3_2_6)
 CVE-2026-78417 (Insufficient verification of data authenticity in the IronVNC client i ...)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[20 Sep 2026] DSA-6509-1 gimp - security update
+	{CVE-2026-78465 CVE-2026-78475 CVE-2026-82328 CVE-2026-90947 CVE-2026-90948 CVE-2026-92248}
+	[trixie] - gimp 3.0.4-3+deb13u11
 [19 Sep 2026] DSA-6508-1 chromium - security update
 	{CVE-2026-93372 CVE-2026-93373 CVE-2026-93374 CVE-2026-93375 CVE-2026-93376 CVE-2026-93377 CVE-2026-93378 CVE-2026-93379 CVE-2026-93380 CVE-2026-93381 CVE-2026-93382 CVE-2026-93383 CVE-2026-93384 CVE-2026-93385 CVE-2026-93386 CVE-2026-93387}
 	[trixie] - chromium 153.0.8010.52-1~deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -49,8 +49,6 @@ freerdp3
 gegl (jmm)
   move to 0.4.72
 --
-gimp (jmm)
---
 gst-plugins-good1.0
 --
 jackson-databind



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0b3ecfe93c24002acccebad5b290c1eb3f9b0de4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0b3ecfe93c24002acccebad5b290c1eb3f9b0de4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/552359c9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list