#1148481 gimp: CVE-2026-90947

Package:
src:gimp
Source:
src:gimp
Submitter:
Moritz Mühlenhoff
Date:
2026-09-19 22:25:05 UTC
Severity:
normal
Tags:
#1148481#5
Date:
2026-09-19 22:24:43 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-90947[0]:
| A flaw was found in GIMP. When processing a specially crafted
| lighting preset file, the Lighting Effects filter does not properly
| validate the number of light sources. This can lead to an out-of-
| bounds write, corrupting memory. An attacker could exploit this by
| convincing a user to open a malicious preset file, potentially
| causing a crash or enabling arbitrary code execution.

https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960

Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90947
https://www.cve.org/CVERecord?id=CVE-2026-90947

Please adjust the affected versions in the BTS as needed.