Bug#1144529: gimp: CVE-2026-59087

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: gimp
Version: 3.2.4-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for gimp.

CVE-2026-59087[0]:
| A flaw was found in the GIMP image manipulation program,
| specifically within its Seattle Filmworks file loader. A remote
| attacker could exploit this vulnerability by tricking a user into
| opening a specially crafted Seattle Filmworks file. This could lead
| to a heap overflow, allowing the attacker to write several kilobytes
| of controlled data beyond the intended memory buffer. Such an
| overflow can result in memory corruption, potentially leading to
| arbitrary code execution or a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59087
    https://www.cve.org/CVERecord?id=CVE-2026-59087
[1] https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491
[2] https://gitlab.gnome.org/GNOME/gimp/-/commit/bb36034bedb06305402ce836129efe8c8d4ad41d

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.