#1142991 gimp: CVE-2026-66758

Package:
src:gimp
Source:
src:gimp
Submitter:
Salvatore Bonaccorso
Date:
2026-07-29 12:45:03 UTC
Severity:
normal
Tags:
#1142991#5
Date:
2026-07-29 12:43:55 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-66758[0]:
| A flaw was found in the file-fits plugin in GIMP. When processing a
| FITS image file, the plugin calculates memory allocation sizes using
| signed 32-bit integers for width and height. If a crafted file sets
| both values to large values, their product exceeds 2^31 and
| overflows, resulting in an undersized heap-based buffer allocation.
| This integer overflow issue results in a heap-based buffer overflow
| when cfitsio subsequently writes a full row of pixels in the buffer,
| causing memory corruption, potentially leading to arbitrary code
| execution or a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66758
https://www.cve.org/CVERecord?id=CVE-2026-66758
[1] https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9

Please adjust the affected versions in the BTS as needed.

Regards,
salvtore