#1148480 gimp: CVE-2026-90948

Package:
src:gimp
Source:
src:gimp
Submitter:
Moritz Mühlenhoff
Date:
2026-09-20 09:37:01 UTC
Severity:
normal
Tags:
#1148480#5
Date:
2026-09-19 22:24:10 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-90948[0]:
| A flaw was found in GIMP's ICO file loader. When processing an ICO
| file containing an embedded PNG image, an integer overflow can occur
| during the calculation of the required buffer size. This leads to an
| undersized buffer being allocated, causing a heap-based buffer
| overflow when the decoded pixel data is written. A remote attacker
| could exploit this by crafting a malicious ICO file, which, when
| opened, could lead to arbitrary code execution or a crash.

https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742

Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90948
https://www.cve.org/CVERecord?id=CVE-2026-90948

Please adjust the affected versions in the BTS as needed.

#1148480#12
Date:
2026-09-20 07:24:44 UTC
From:
To:
Version: 3.2.6-1

This is https://salsa.debian.org/gnome-team/extras/gimp/-/blob/debian/latest/debian/patches/16742.patch

Thank you,
Jeremy Bícha