#1148969 gimp: CVE-2026-97185

Package:
src:gimp
Source:
src:gimp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-25 19:19:03 UTC
Severity:
normal
Tags:
#1148969#5
Date:
2026-09-25 19:18:26 UTC
From:
To:
Hi,

The following vulnerability was published for gimp.

CVE-2026-97185[0]:
| A flaw was found in GIMP. When processing a specially crafted
| GIMPressionist preset file, the plug-in does not properly validate
| vector indices before writing into fixed-size arrays. This can lead
| to an out-of-bounds write, corrupting memory. An attacker could
| exploit this by convincing a user to load a malicious preset file,
| potentially causing a crash or enabling arbitrary code execution.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-97185
https://www.cve.org/CVERecord?id=CVE-2026-97185
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788
[2] https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore