#1145874 gimp: CVE-2026-78475

Package:
src:gimp
Source:
src:gimp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-21 18:07:02 UTC
Severity:
normal
Tags:
#1145874#5
Date:
2026-08-27 12:50:01 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-78475[0]:
| A flaw was found in the file-pix (ESM) plugin in GIMP. When
| processing a specially crafted PIX image file, the plugin allocates
| a Variable-Length Array (VLA) on the stack without proper bounds
| checking, causing an unbounded stack allocation followed by a
| 21-byte stack over-read. This can result in a denial of service due
| to stack exhaustion and a limited information disclosure of stack
| memory contents into an intermediate file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78475
https://www.cve.org/CVERecord?id=CVE-2026-78475
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1145874#12
Date:
2026-09-12 11:51:52 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
gimp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145874@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated gimp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 11:13:11 +0200
Source: gimp
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.2.6-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Extras Maintainers <pkg-gnome-extras-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141415 1142990 1142991 1142992 1143023 1144520 1144526 1144528 1144529 1145871 1145872 1145874 1145875 1145892 1145893 1145894 1145895 1145896 1145897 1145898 1145899 1145900 1146132 1146133 1146134 1146135
Changes:
 gimp (3.2.6-1) unstable; urgency=high
 .
   * New upstream release
     - CVE-2026-18301 (Closes: #1145892)
     - CVE-2026-18302 (Closes: #1145893)
     - CVE-2026-18303 (Closes: #1145894)
     - CVE-2026-18304 (Closes: #1145895)
     - CVE-2026-18305 (Closes: #1145896)
     - CVE-2026-18306 (Closes: #1145897)
     - CVE-2026-18307 (Closes: #1145898)
     - CVE-2026-18308 (Closes: #1145899)
     - CVE-2026-18309 (Closes: #1145900)
     - CVE-2026-42170
     - CVE-2026-58379 (Closes: #1141415)
     - CVE-2026-59087 (Closes: #1144529)
     - CVE-2026-59088 (Closes: #1144528)
     - CVE-2026-59089 (Closes: #1143023)
     - CVE-2026-59090 (Closes: #1144526)
     - CVE-2026-59091 (Closes: #1144520)
     - CVE-2026-66791
     - CVE-2026-66757 (Closes: #1142990)
     - CVE-2026-66758 (Closes: #1142991)
     - CVE-2026-66759 (Closes: #1142992)
     - CVE-2026-78465 (Closes: #1145875)
     - CVE-2026-78475 (Closes: #1145874)
     - CVE-2026-79902 (Closes: #1145872)
     - CVE-2026-80101 (Closes: #1145871)
     - CVE-2026-82324 (Closes: #1146132)
     - CVE-2026-82328 (Closes: #1146133)
     - CVE-2026-82330 (Closes: #1146134)
     - CVE-2026-82343 (Closes: #1146135)
     - CVE-2026-62438
     - CVE-2026-62439
     - GIMP #16581
     - GIMP #16682
     - GIMP #16753
     - ZDI-CAN-29400
   * Cherry-pick additional security improvements
     - 16742.patch
     - 16753.patch
     - 2997.patch
   * debian/libgimp-3.0-0.symbols: Add new symbols
   * Remove s390x patch: applied in new release
   * Update debhelper compat to 14
Checksums-Sha1:
 4a22e9134d45d0b6810167ab26ca4264f8dbd125 3901 gimp_3.2.6-1.dsc
 1c16f79caeaf946faa05c086277a1052d2d0dbba 35004888 gimp_3.2.6.orig.tar.xz
 ee35851ee5a48466be45f36cc5da69a43b85d23b 69348 gimp_3.2.6-1.debian.tar.xz
 67c46a24c01b7c3dfd149c9e97eb37d453e982bf 11549 gimp_3.2.6-1_source.buildinfo
Checksums-Sha256:
 1b95a3139a90bd9933e84cf7bf89a1df9704426367b44e95f68aa710ae91c09b 3901 gimp_3.2.6-1.dsc
 40b15e90ad0c0c631b76da3c467ea9847fa5c24f37413ac5b492804860a28cd8 35004888 gimp_3.2.6.orig.tar.xz
 f385d5e1d3117134185be6ff8fbf0874c0eff55cc01564cf75dd9a101510330b 69348 gimp_3.2.6-1.debian.tar.xz
 e996eb85e15f4921c3f6b8d031b8a15f334a5376dd2736acd1b6417e3d499465 11549 gimp_3.2.6-1_source.buildinfo
Files:
 9d360197e73a1e6ca5d5156b1d4a4211 3901 graphics optional gimp_3.2.6-1.dsc
 d4dbb4681eb28e4e6455666c880e5f1b 35004888 graphics optional gimp_3.2.6.orig.tar.xz
 dea33bbb5c6eac11acc127e7ea199fc1 69348 graphics optional gimp_3.2.6-1.debian.tar.xz
 9e019ee9d6f1d7490738858b4762154c 11549 graphics optional gimp_3.2.6-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqlN6kACgkQ5mx3Wuv+
bH2Avw//de8XxAgPvylfZwqotQdddL7nYb7nqddYONmXg06pYbii8iZJV6RwBz+B
QpD97dyVAz0FzrR9r12+8gXDWnH2GAZL2+jSnxAqdNTrQ8mDnU67X9GUOJF5Yovz
2xFa44L0vF+cbpbjCdLIziFVJ3Fwz//StlrWXw1qtgm92KaIokA5erKUaxKY5re3
+zEomNOsDBrCbFZDVieJrejz/AZAG2vfS3kOXcQeWn/lvszASfqc8kYbzqnpRIo9
q3qHRM4ANMzsbDNXOvsYxLuzDHFr4fdMU97OCL8uTllWUFsEkZdVD0n0Tx7y6lly
JPc//t989FDA2Pqv2ZojDM6rIVyOrjI5diwv780PYov9awdCW9ushZOn8XL4ge5U
UXi0F9vrnVfpAFUIuHdP9XcEVkyO88QXPjxdmufFhLIRdN085UJgHvo0Y9zTKqTU
kkXsE+novDBWvKavFfZc5kmhnC4ci9pyZsdD75sK6GpEt57ITvJblWKqCuSVby9C
M7AIMeZq9PkkVZvrNlLWSYClmf0EjCsdaqcJo0/O4/ddVMDnThkezogOUow92uJb
sdQRyppRVWtNcyYqUSjLGQPCk41rEPPw44Mb+YsqMuzI1BEPa4iYWMBC9bc0VMKB
STBNZJsYOSqhWKVlZqUbC7TAPq4Ja9hgNB0qbl9mhMYzu+l41Xs=
=pSrF
-----END PGP SIGNATURE-----

#1145874#17
Date:
2026-09-21 18:04:41 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
gimp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145874@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Mühlenhoff <jmm@debian.org> (supplier of updated gimp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 17:17:20 +0200
Source: gimp
Architecture: source
Version: 3.0.4-3+deb13u11
Distribution: trixie-security
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Moritz Mühlenhoff <jmm@debian.org>
Closes: 1145874 1145875 1146133
Changes:
 gimp (3.0.4-3+deb13u11) trixie-security; urgency=medium
 .
   * CVE-2026-92248
   * CVE-2026-90947
   * CVE-2026-82328 (Closes: #1146133)
   * CVE-2026-90948
   * CVE-2026-78465 (Closes: #1145875)
   * CVE-2026-78475 (Closes: #1145874)
Checksums-Sha1:
 13dda2ed30326c4690b903cd3e2e65b5f707f12e 3927 gimp_3.0.4-3+deb13u11.dsc
 a9c615e90389b65ecead2e9e0d04a565b6e5c0dc 86332 gimp_3.0.4-3+deb13u11.debian.tar.xz
 6f7048154eafa4f475cb64bde61d3d9b821fccc4 24914 gimp_3.0.4-3+deb13u11_amd64.buildinfo
Checksums-Sha256:
 d4db578048a46b520dfe8dec836e5d16d302a70b1852ebc6193c5f41f6974710 3927 gimp_3.0.4-3+deb13u11.dsc
 f1110c39828bcb9ce8a4cca8ee544f034aeb8b3228970eeada64848760c1bbbf 86332 gimp_3.0.4-3+deb13u11.debian.tar.xz
 ff9127936247ec838d39aebf00ad8eb0f0cdec5862a31ac87eebd914dfae028f 24914 gimp_3.0.4-3+deb13u11_amd64.buildinfo
Files:
 815da2585a2e9f22e37267acfaba0ce3 3927 graphics optional gimp_3.0.4-3+deb13u11.dsc
 8c4b0fd556408d77adcc1b0ecc9efcaa 86332 graphics optional gimp_3.0.4-3+deb13u11.debian.tar.xz
 3691b0d5a673607909c90b46bd9f701f 24914 graphics optional gimp_3.0.4-3+deb13u11_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqu4zwACgkQEMKTtsN8
TjaReg/8DFDEzv4hquNwoFZHyq/8DoHcnrIk8BASOOHaaqZt/FtwI1qOpuPtpSm6
JP6YPkx/0hAb58wLeMAT/AwQEbMQmCPSPgdc1xLqndx9kcZSZUzrchpcdRa96qJi
mSssk3g64ZmI1vZSC4K+V+l2uLJLg3ERHza3d/hmjT97oq17dn0zHBof2robz7zQ
Q5N7GnluEvcKltVG0+mWR9zsRlbMUC3nAYXoLjaR/Tgf8LamKR2EoDte9uJybdH0
8HFge0zxVHPpjwfP/0QTKW7KV0H9k0fN6+UCTEnx3Xzs1PfpCbwQVZkHr2fI2D20
a8lGykLNteAuO0rWluhnYdiBTEPRE0UEWonlDgr0jxCFXL7Fxv7+dlKWNEODaNDa
fbN0iKh606D6RuzeE5XdLwOyX0mXY8TinlRMKSKtqwNN99SJQIyH+qsD84QD2b7L
pK6q/7lsR0KbTll61AObarma9jOrDq/sk71zA2r8HT2z7ZpBrPgsxQWyXm4WGtpb
VUc0fcOdikYFxyRBjyFlcH/edbUZvl4uxkTP1ULKHqLbRFN/5rq10UN0B/SgRKvt
1YP6JQkpqekHGE8+VGB5CTIZ29cO3Z0/SyGVzxi6ZgV8f0QzrZGMtJjZRqJ/dFqF
AvGALqV/BdYJw1uhBIwkCFB13o44l16/j/BamEZ96c4JHSUtRp4=
=GskM
-----END PGP SIGNATURE-----