#1148477 gimp: CVE-2026-92248

Package:
src:gimp
Source:
src:gimp
Submitter:
Moritz Mühlenhoff
Date:
2026-09-20 10:19:03 UTC
Severity:
normal
Tags:
#1148477#5
Date:
2026-09-19 22:22:53 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-92248[0]:
| A flaw was found in the file-psd plugin in GIMP. When generating a
| thumbnail preview for a specially crafted PSD (Photoshop Document)
| image file, an integer overflow occurs during the multiplication of
| values from an embedded JPEG header. This leads to an undersized
| heap allocation, resulting in a heap-based buffer overflow when the
| image data is decoded. This buffer overflow corrupts adjacent heap
| objects, allowing for a controlled memory write that can result in
| an application crash or arbitrary code execution.

https://gitlab.gnome.org/GNOME/gimp/-/work_items/16775
https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3009
https://gitlab.gnome.org/GNOME/gimp/-/commit/6b1e668699ebebc35152ad6c3db4b445cd78b7df


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-92248
https://www.cve.org/CVERecord?id=CVE-2026-92248

Please adjust the affected versions in the BTS as needed.

#1148477#10
Date:
2026-09-20 10:17:23 UTC
From:
To:
Hello,

Bug #1148477 in gimp reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/extras/gimp/-/commit/e875c84a84c808f30459378451e253284dae734c
------------------------------------------------------------------------
SECURITY UPDATE

- debian/patches/CVE-2026-92248:
  Integer overflow in plug-ins/file-psd/psd-image-res-load.c
  + CVE-2026-92248 (Closes: #1148477)

Gbp-Dch: Full
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1148477