Security advisory for Krita < 5.2.13

David Edmundson <[email protected]> Mon, 29 Sep 2025 22:14:10 +0100
Newsgroups gmane.comp.kde.announce
Message-ID <CAGeFrHCqEhEt3O-8rHBPCtLG4_5ZZX003V3tf4CK7Hog=f2S+g@mail.gmail.com>
A new security advisory for Krita has been announced.

KDE Project Security Advisory
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D

Title:           Krita: Heap-based buffer overflow when parsing TGA files
Risk Rating:     Medium
CVE:             CVE-2025-59820
Versions:        Affected versions of Krita prior to 5.2.13
Author:          KDE Security Team
Date:            29/09/2025

Overview
=3D=3D=3D=3D=3D=3D=3D=3D

A vulnerability was identified in Krita=E2=80=99s TGA file parser that coul=
d
result in a heap-based buffer overflow during file processing.

Impact
=3D=3D=3D=3D=3D=3D

Opening a specially crafted TGA file in Krita may trigger a heap-based
buffer overflow, potentially leading to application crashes or
potentially in the worst case, code execution.

Workaround
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Avoid opening TGA files from unknown sources in Krita until the fix is appl=
ied.

Solution
=3D=3D=3D=3D=3D=3D=3D=3D

Update to the latest release of Krita 5.2.13 or apply
the following patch:
https://commits.kde.org/krita/6d3651ac4df88efb68e013d21061de9846e83fe8

Credits
=3D=3D=3D=3D=3D=3D=3D

This issue was reported by Trend Micro.