[Pkg-gnome-extras-maintainers] Bug#1148477: gimp: CVE-2026-92248
Moritz Mühlenhoff
jmm at inutil.org
Sat Sep 19 23:22:53 BST 2026
Source: gimp
X-Debbugs-CC: team at security.debian.org
Severity: grave
Tags: security
Hi,
The following vulnerability was published for gimp.
CVE-2026-92248[0]:
| A flaw was found in the file-psd plugin in GIMP. When generating a
| thumbnail preview for a specially crafted PSD (Photoshop Document)
| image file, an integer overflow occurs during the multiplication of
| values from an embedded JPEG header. This leads to an undersized
| heap allocation, resulting in a heap-based buffer overflow when the
| image data is decoded. This buffer overflow corrupts adjacent heap
| objects, allowing for a controlled memory write that can result in
| an application crash or arbitrary code execution.
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16775
https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3009
https://gitlab.gnome.org/GNOME/gimp/-/commit/6b1e668699ebebc35152ad6c3db4b445cd78b7df
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-92248
https://www.cve.org/CVERecord?id=CVE-2026-92248
Please adjust the affected versions in the BTS as needed.
More information about the pkg-gnome-extras-maintainers
mailing list