[Pkg-gnome-extras-maintainers] Bug#1148481: gimp: CVE-2026-90947

Moritz Mühlenhoff jmm at inutil.org
Sat Sep 19 23:24:43 BST 2026


Source: gimp
X-Debbugs-CC: team at security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerability was published for gimp.

CVE-2026-90947[0]:
| A flaw was found in GIMP. When processing a specially crafted
| lighting preset file, the Lighting Effects filter does not properly
| validate the number of light sources. This can lead to an out-of-
| bounds write, corrupting memory. An attacker could exploit this by
| convincing a user to open a malicious preset file, potentially
| causing a crash or enabling arbitrary code execution.

https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960

Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90947
    https://www.cve.org/CVERecord?id=CVE-2026-90947

Please adjust the affected versions in the BTS as needed.



More information about the pkg-gnome-extras-maintainers mailing list