Bug#1145018: gegl: CVE-2026-18300

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: gegl
Version: 1:0.4.70-4
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1:0.4.62-2

Hi,

The following vulnerability was published for gegl.

CVE-2026-18300[0]:
| GIMP HDR File Parsing Integer Overflow Remote Code Execution
| Vulnerability. This vulnerability allows remote attackers to execute
| arbitrary code on affected installations of GIMP. User interaction
| is required to exploit this vulnerability in that the target must
| visit a malicious page or open a malicious file.  The specific flaw
| exists within the parsing of HDR files. The issue results from the
| lack of proper validation of user-supplied data, which can result in
| an integer overflow before allocating a buffer. An attacker can
| leverage this vulnerability to execute code in the context of the
| current process. Was ZDI-CAN-29289.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18300
    https://www.cve.org/CVERecord?id=CVE-2026-18300
[1] https://www.zerodayinitiative.com/advisories/ZDI-26-453/
[2] https://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.