#1142990 gimp: CVE-2026-66757

Package:
src:gimp
Source:
src:gimp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 11:53:02 UTC
Severity:
normal
Tags:
#1142990#5
Date:
2026-07-29 12:42:01 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-66757[0]:
| A flaw was found in the file-sgi plugin in GIMP. When processing an
| RLE-compressed SGI image, the plugin allocates memory for a row
| table. The image header dimensions (ysize and zsize) are read as
| 16-bit unsigned integers. If a crafted file sets both dimensions to
| their maximum value (65535), the multiplication ysize * zsize
| overflows the standard 32-bit int boundary before being passed to
| calloc. This integer overflow issue results in undefined behavior,
| aborting the plugin and causing a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66757
https://www.cve.org/CVERecord?id=CVE-2026-66757
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494
[2] https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2884

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142990#12
Date:
2026-09-12 11:51:52 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
gimp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142990@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated gimp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 11:13:11 +0200
Source: gimp
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.2.6-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Extras Maintainers <pkg-gnome-extras-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141415 1142990 1142991 1142992 1143023 1144520 1144526 1144528 1144529 1145871 1145872 1145874 1145875 1145892 1145893 1145894 1145895 1145896 1145897 1145898 1145899 1145900 1146132 1146133 1146134 1146135
Changes:
 gimp (3.2.6-1) unstable; urgency=high
 .
   * New upstream release
     - CVE-2026-18301 (Closes: #1145892)
     - CVE-2026-18302 (Closes: #1145893)
     - CVE-2026-18303 (Closes: #1145894)
     - CVE-2026-18304 (Closes: #1145895)
     - CVE-2026-18305 (Closes: #1145896)
     - CVE-2026-18306 (Closes: #1145897)
     - CVE-2026-18307 (Closes: #1145898)
     - CVE-2026-18308 (Closes: #1145899)
     - CVE-2026-18309 (Closes: #1145900)
     - CVE-2026-42170
     - CVE-2026-58379 (Closes: #1141415)
     - CVE-2026-59087 (Closes: #1144529)
     - CVE-2026-59088 (Closes: #1144528)
     - CVE-2026-59089 (Closes: #1143023)
     - CVE-2026-59090 (Closes: #1144526)
     - CVE-2026-59091 (Closes: #1144520)
     - CVE-2026-66791
     - CVE-2026-66757 (Closes: #1142990)
     - CVE-2026-66758 (Closes: #1142991)
     - CVE-2026-66759 (Closes: #1142992)
     - CVE-2026-78465 (Closes: #1145875)
     - CVE-2026-78475 (Closes: #1145874)
     - CVE-2026-79902 (Closes: #1145872)
     - CVE-2026-80101 (Closes: #1145871)
     - CVE-2026-82324 (Closes: #1146132)
     - CVE-2026-82328 (Closes: #1146133)
     - CVE-2026-82330 (Closes: #1146134)
     - CVE-2026-82343 (Closes: #1146135)
     - CVE-2026-62438
     - CVE-2026-62439
     - GIMP #16581
     - GIMP #16682
     - GIMP #16753
     - ZDI-CAN-29400
   * Cherry-pick additional security improvements
     - 16742.patch
     - 16753.patch
     - 2997.patch
   * debian/libgimp-3.0-0.symbols: Add new symbols
   * Remove s390x patch: applied in new release
   * Update debhelper compat to 14
Checksums-Sha1:
 4a22e9134d45d0b6810167ab26ca4264f8dbd125 3901 gimp_3.2.6-1.dsc
 1c16f79caeaf946faa05c086277a1052d2d0dbba 35004888 gimp_3.2.6.orig.tar.xz
 ee35851ee5a48466be45f36cc5da69a43b85d23b 69348 gimp_3.2.6-1.debian.tar.xz
 67c46a24c01b7c3dfd149c9e97eb37d453e982bf 11549 gimp_3.2.6-1_source.buildinfo
Checksums-Sha256:
 1b95a3139a90bd9933e84cf7bf89a1df9704426367b44e95f68aa710ae91c09b 3901 gimp_3.2.6-1.dsc
 40b15e90ad0c0c631b76da3c467ea9847fa5c24f37413ac5b492804860a28cd8 35004888 gimp_3.2.6.orig.tar.xz
 f385d5e1d3117134185be6ff8fbf0874c0eff55cc01564cf75dd9a101510330b 69348 gimp_3.2.6-1.debian.tar.xz
 e996eb85e15f4921c3f6b8d031b8a15f334a5376dd2736acd1b6417e3d499465 11549 gimp_3.2.6-1_source.buildinfo
Files:
 9d360197e73a1e6ca5d5156b1d4a4211 3901 graphics optional gimp_3.2.6-1.dsc
 d4dbb4681eb28e4e6455666c880e5f1b 35004888 graphics optional gimp_3.2.6.orig.tar.xz
 dea33bbb5c6eac11acc127e7ea199fc1 69348 graphics optional gimp_3.2.6-1.debian.tar.xz
 9e019ee9d6f1d7490738858b4762154c 11549 graphics optional gimp_3.2.6-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqlN6kACgkQ5mx3Wuv+
bH2Avw//de8XxAgPvylfZwqotQdddL7nYb7nqddYONmXg06pYbii8iZJV6RwBz+B
QpD97dyVAz0FzrR9r12+8gXDWnH2GAZL2+jSnxAqdNTrQ8mDnU67X9GUOJF5Yovz
2xFa44L0vF+cbpbjCdLIziFVJ3Fwz//StlrWXw1qtgm92KaIokA5erKUaxKY5re3
+zEomNOsDBrCbFZDVieJrejz/AZAG2vfS3kOXcQeWn/lvszASfqc8kYbzqnpRIo9
q3qHRM4ANMzsbDNXOvsYxLuzDHFr4fdMU97OCL8uTllWUFsEkZdVD0n0Tx7y6lly
JPc//t989FDA2Pqv2ZojDM6rIVyOrjI5diwv780PYov9awdCW9ushZOn8XL4ge5U
UXi0F9vrnVfpAFUIuHdP9XcEVkyO88QXPjxdmufFhLIRdN085UJgHvo0Y9zTKqTU
kkXsE+novDBWvKavFfZc5kmhnC4ci9pyZsdD75sK6GpEt57ITvJblWKqCuSVby9C
M7AIMeZq9PkkVZvrNlLWSYClmf0EjCsdaqcJo0/O4/ddVMDnThkezogOUow92uJb
sdQRyppRVWtNcyYqUSjLGQPCk41rEPPw44Mb+YsqMuzI1BEPa4iYWMBC9bc0VMKB
STBNZJsYOSqhWKVlZqUbC7TAPq4Ja9hgNB0qbl9mhMYzu+l41Xs=
=pSrF
-----END PGP SIGNATURE-----