Hi, The following vulnerability was published for gimp. CVE-2026-66759[0]: | A flaw was found in the file-icns plugin in GIMP. When applying a | decompressed mask during ICNS image processing, the plugin reads | from the mask data buffer without verifying if the cursor exceeds | the allocated resource size. If a crafted file contains a truncated | mask resource, the icns_decompress function continues reading past | the bounds of the buffer. This out-of-bounds read vulnerability | results in information disclosure of heap contents, where memory | contents are leaked as alpha channel pixel values, or a crash | leading to a denial of service if unmapped memory is accessed. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-66759 https://www.cve.org/CVERecord?id=CVE-2026-66759 [1] https://gitlab.gnome.org/GNOME/gimp/-/issues/16528 [2] https://gitlab.gnome.org/GNOME/gimp/-/commit/abb3129a8ecb79bf3af6df03bc35ddf8f7aaba20 Please adjust the affected versions in the BTS as needed. Regards, Salvatore