Hi, The following vulnerability was published for gimp. CVE-2026-59088[0]: | A flaw was found in GIMP. A signed integer overflow vulnerability | exists in the `file-fli` plugin when processing FLI image files. | This occurs due to an incorrect calculation during memory allocation | for image buffers, where the multiplication of image width and | height can exceed the maximum integer value. A remote attacker could | exploit this by tricking a user into opening a specially crafted FLI | file, leading to the application crashing and resulting in a denial | of service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59088 https://www.cve.org/CVERecord?id=CVE-2026-59088 [1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492 [2] https://gitlab.gnome.org/GNOME/gimp/-/commit/1db4690bde3a349df046f85a4ee9a71af8492216 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of gimp, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1144528@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Moritz Mühlenhoff <jmm@debian.org> (supplier of updated gimp package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 21 Aug 2026 21:03:47 +0200 Source: gimp Architecture: source Version: 3.0.4-3+deb13u10 Distribution: trixie-security Urgency: medium Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Moritz Mühlenhoff <jmm@debian.org> Closes: 1141415 1142991 1142992 1144526 1144528 Changes: gimp (3.0.4-3+deb13u10) trixie-security; urgency=medium . * CVE-2026-18301 * CVE-2026-18302 * CVE-2026-18303 * CVE-2026-18304 * CVE-2026-18305 * CVE-2026-18306 * CVE-2026-18307 * CVE-2026-18308 * CVE-2026-42170 * CVE-2026-58379 (Closes: #1141415) * CVE-2026-58380 * CVE-2026-58381 * CVE-2026-58384 * CVE-2026-59088 (Closes: #1144528) * CVE-2026-59090 (Closes: #1144526) * CVE-2026-66758 (Closes: #1142991) * CVE-2026-66759 (Closes: #1142992) Checksums-Sha1: cd972aeb0d9f685365e363b9133057fa46a63da7 3927 gimp_3.0.4-3+deb13u10.dsc 4782d6526290f44b2a1802e2c3d531b1351cf2b5 83164 gimp_3.0.4-3+deb13u10.debian.tar.xz 43b2f38be681de40ed553268e23e15962c188529 24914 gimp_3.0.4-3+deb13u10_amd64.buildinfo Checksums-Sha256: 911db979b8c250dc3d3bec20b73a60da9bfffd79cb6bead06445d710d5c3be5a 3927 gimp_3.0.4-3+deb13u10.dsc 36b090a0a9d0b15e1ad61ee6b92ee354f746883b21ac91912ec8b36d4cad512f 83164 gimp_3.0.4-3+deb13u10.debian.tar.xz 181c27e40d9ab7a72f8b6bedf0cfc3845bd5570c47c2cbf45863b68f32fdf586 24914 gimp_3.0.4-3+deb13u10_amd64.buildinfo Files: ce3bc966c3356a389d10fe57085c3864 3927 graphics optional gimp_3.0.4-3+deb13u10.dsc c7d020d9882dedc5fec8088948c456c4 83164 graphics optional gimp_3.0.4-3+deb13u10.debian.tar.xz acc50a47cc627b16bd7d001dfd6bfe89 24914 graphics optional gimp_3.0.4-3+deb13u10_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqIyDcACgkQEMKTtsN8 TjYBPg//cezZF/XP9kXguhrSh7o6ODerTuaQD1rM2ocYgr7V5L1xZaWfHBkBYlzf 85w+NVvlP0Ai/jgf6yNtIjppFAeBPFAFS7wE61wUHi3LzqpIZMDiUZ+6Rx/MvKgW P++3HYU2TX9Gv+csgsknODTOxbUviimCwT4LXHJM/rmsbeCK5sP3ALpYD9u+330f ZeB5NgAiKDaR4SXdko76L/lO7/OnYxnNb8n8nQRJh2w4+yMK/HTu/U1sRFvSNiWD 7U5oc56kTvn1WLYaDA8SOxoe4PHxxOBbGXwSN8cLCLzgsCI/Qrss5jiLciALDwbY 0Oz8AmqcxNeTdkyItBRgrj/rQDo8H9LOonifY7yoMHLZ+JObviTzA6RoxJHZsN33 kVUp8YNSL0Acz2ixcKo8cA/JH2oN9U81omirCsb65XTsBMcALThBlTXw1v0M2HAg UZV668ioBI46/xLbR4xP/da3qv5fobtYdPI9e00iFPgcGG8tWvwXXgMMkcjNgBNV 7BBFyspJe+o+eJXjHwb2d5Er0CRVUqqxBiT1aDK2aAhwDn6HxXYxNBMjUYC45hwc J+qO693lX1I2QqxZiTsnZ1ChGDVsQ+tgPDAhik3veRCt8FfuiV3R3aidozPt/m4c rlswUB7Py5IwciZ0a5nZelbsy/GHn2pEVr7QH/941KycBR3icKA= =TaLC -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
gimp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144528@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated gimp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 11:13:11 +0200
Source: gimp
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.2.6-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Extras Maintainers <pkg-gnome-extras-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141415 1142990 1142991 1142992 1143023 1144520 1144526 1144528 1144529 1145871 1145872 1145874 1145875 1145892 1145893 1145894 1145895 1145896 1145897 1145898 1145899 1145900 1146132 1146133 1146134 1146135
Changes:
gimp (3.2.6-1) unstable; urgency=high
.
* New upstream release
- CVE-2026-18301 (Closes: #1145892)
- CVE-2026-18302 (Closes: #1145893)
- CVE-2026-18303 (Closes: #1145894)
- CVE-2026-18304 (Closes: #1145895)
- CVE-2026-18305 (Closes: #1145896)
- CVE-2026-18306 (Closes: #1145897)
- CVE-2026-18307 (Closes: #1145898)
- CVE-2026-18308 (Closes: #1145899)
- CVE-2026-18309 (Closes: #1145900)
- CVE-2026-42170
- CVE-2026-58379 (Closes: #1141415)
- CVE-2026-59087 (Closes: #1144529)
- CVE-2026-59088 (Closes: #1144528)
- CVE-2026-59089 (Closes: #1143023)
- CVE-2026-59090 (Closes: #1144526)
- CVE-2026-59091 (Closes: #1144520)
- CVE-2026-66791
- CVE-2026-66757 (Closes: #1142990)
- CVE-2026-66758 (Closes: #1142991)
- CVE-2026-66759 (Closes: #1142992)
- CVE-2026-78465 (Closes: #1145875)
- CVE-2026-78475 (Closes: #1145874)
- CVE-2026-79902 (Closes: #1145872)
- CVE-2026-80101 (Closes: #1145871)
- CVE-2026-82324 (Closes: #1146132)
- CVE-2026-82328 (Closes: #1146133)
- CVE-2026-82330 (Closes: #1146134)
- CVE-2026-82343 (Closes: #1146135)
- CVE-2026-62438
- CVE-2026-62439
- GIMP #16581
- GIMP #16682
- GIMP #16753
- ZDI-CAN-29400
* Cherry-pick additional security improvements
- 16742.patch
- 16753.patch
- 2997.patch
* debian/libgimp-3.0-0.symbols: Add new symbols
* Remove s390x patch: applied in new release
* Update debhelper compat to 14
Checksums-Sha1:
4a22e9134d45d0b6810167ab26ca4264f8dbd125 3901 gimp_3.2.6-1.dsc
1c16f79caeaf946faa05c086277a1052d2d0dbba 35004888 gimp_3.2.6.orig.tar.xz
ee35851ee5a48466be45f36cc5da69a43b85d23b 69348 gimp_3.2.6-1.debian.tar.xz
67c46a24c01b7c3dfd149c9e97eb37d453e982bf 11549 gimp_3.2.6-1_source.buildinfo
Checksums-Sha256:
1b95a3139a90bd9933e84cf7bf89a1df9704426367b44e95f68aa710ae91c09b 3901 gimp_3.2.6-1.dsc
40b15e90ad0c0c631b76da3c467ea9847fa5c24f37413ac5b492804860a28cd8 35004888 gimp_3.2.6.orig.tar.xz
f385d5e1d3117134185be6ff8fbf0874c0eff55cc01564cf75dd9a101510330b 69348 gimp_3.2.6-1.debian.tar.xz
e996eb85e15f4921c3f6b8d031b8a15f334a5376dd2736acd1b6417e3d499465 11549 gimp_3.2.6-1_source.buildinfo
Files:
9d360197e73a1e6ca5d5156b1d4a4211 3901 graphics optional gimp_3.2.6-1.dsc
d4dbb4681eb28e4e6455666c880e5f1b 35004888 graphics optional gimp_3.2.6.orig.tar.xz
dea33bbb5c6eac11acc127e7ea199fc1 69348 graphics optional gimp_3.2.6-1.debian.tar.xz
9e019ee9d6f1d7490738858b4762154c 11549 graphics optional gimp_3.2.6-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqlN6kACgkQ5mx3Wuv+
bH2Avw//de8XxAgPvylfZwqotQdddL7nYb7nqddYONmXg06pYbii8iZJV6RwBz+B
QpD97dyVAz0FzrR9r12+8gXDWnH2GAZL2+jSnxAqdNTrQ8mDnU67X9GUOJF5Yovz
2xFa44L0vF+cbpbjCdLIziFVJ3Fwz//StlrWXw1qtgm92KaIokA5erKUaxKY5re3
+zEomNOsDBrCbFZDVieJrejz/AZAG2vfS3kOXcQeWn/lvszASfqc8kYbzqnpRIo9
q3qHRM4ANMzsbDNXOvsYxLuzDHFr4fdMU97OCL8uTllWUFsEkZdVD0n0Tx7y6lly
JPc//t989FDA2Pqv2ZojDM6rIVyOrjI5diwv780PYov9awdCW9ushZOn8XL4ge5U
UXi0F9vrnVfpAFUIuHdP9XcEVkyO88QXPjxdmufFhLIRdN085UJgHvo0Y9zTKqTU
kkXsE+novDBWvKavFfZc5kmhnC4ci9pyZsdD75sK6GpEt57ITvJblWKqCuSVby9C
M7AIMeZq9PkkVZvrNlLWSYClmf0EjCsdaqcJo0/O4/ddVMDnThkezogOUow92uJb
sdQRyppRVWtNcyYqUSjLGQPCk41rEPPw44Mb+YsqMuzI1BEPa4iYWMBC9bc0VMKB
STBNZJsYOSqhWKVlZqUbC7TAPq4Ja9hgNB0qbl9mhMYzu+l41Xs=
=pSrF
-----END PGP SIGNATURE-----