Bug#1142991: gimp: CVE-2026-66758

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: gimp
Version: 3.2.4-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for gimp.

CVE-2026-66758[0]:
| A flaw was found in the file-fits plugin in GIMP. When processing a
| FITS image file, the plugin calculates memory allocation sizes using
| signed 32-bit integers for width and height. If a crafted file sets
| both values to large values, their product exceeds 2^31 and
| overflows, resulting in an undersized heap-based buffer allocation.
| This integer overflow issue results in a heap-based buffer overflow
| when cfitsio subsequently writes a full row of pixels in the buffer,
| causing memory corruption, potentially leading to arbitrary code
| execution or a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66758
    https://www.cve.org/CVERecord?id=CVE-2026-66758
[1] https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9

Please adjust the affected versions in the BTS as needed.

Regards,
salvtore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.