[Pkg-gnome-extras-maintainers] Bug#1142991: gimp: CVE-2026-66758
Salvatore Bonaccorso
carnil at debian.org
Wed Jul 29 13:43:55 BST 2026
Source: gimp
Version: 3.2.4-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for gimp.
CVE-2026-66758[0]:
| A flaw was found in the file-fits plugin in GIMP. When processing a
| FITS image file, the plugin calculates memory allocation sizes using
| signed 32-bit integers for width and height. If a crafted file sets
| both values to large values, their product exceeds 2^31 and
| overflows, resulting in an undersized heap-based buffer allocation.
| This integer overflow issue results in a heap-based buffer overflow
| when cfitsio subsequently writes a full row of pixels in the buffer,
| causing memory corruption, potentially leading to arbitrary code
| execution or a denial of service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-66758
https://www.cve.org/CVERecord?id=CVE-2026-66758
[1] https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9
Please adjust the affected versions in the BTS as needed.
Regards,
salvtore
More information about the pkg-gnome-extras-maintainers
mailing list