#1148895 gimp: CVE-2026-96545

Package:
src:gimp
Source:
src:gimp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 18:37:02 UTC
Severity:
normal
Tags:
#1148895#5
Date:
2026-09-24 18:35:23 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-96545[0]:
| An out-of-bounds heap read flaw was found in GIMP's TIM image
| loader. When a user opens a crafted 4bpp TIM image that causes
| promotion to an RGBA layer, the file-tim plug-in allocates an
| undersized row buffer but processes it using the larger RGBA row
| size. This can copy adjacent heap contents into the decoded image
| and may crash the plug-in.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-96545
https://www.cve.org/CVERecord?id=CVE-2026-96545
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16791
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/8d6825ba0074a40834d23c2ddecd1f50276fde52

Regards,
Salvatore