[Pkg-gnome-extras-maintainers] Bug#1148481: gimp: CVE-2026-90947
Moritz Mühlenhoff
jmm at inutil.org
Sat Sep 19 23:24:43 BST 2026
Source: gimp
X-Debbugs-CC: team at security.debian.org
Severity: grave
Tags: security
Hi,
The following vulnerability was published for gimp.
CVE-2026-90947[0]:
| A flaw was found in GIMP. When processing a specially crafted
| lighting preset file, the Lighting Effects filter does not properly
| validate the number of light sources. This can lead to an out-of-
| bounds write, corrupting memory. An attacker could exploit this by
| convincing a user to open a malicious preset file, potentially
| causing a crash or enabling arbitrary code execution.
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-90947
https://www.cve.org/CVERecord?id=CVE-2026-90947
Please adjust the affected versions in the BTS as needed.
More information about the pkg-gnome-extras-maintainers
mailing list