Your message dated Mon, 31 Aug 2026 13:48:36 +0000
with message-id <[email protected]>
and subject line Bug#1142991: fixed in gimp 3.0.4-3+deb13u10
has caused the Debian Bug report #1142991,
regarding gimp: CVE-2026-66758
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142991: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142991
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: gimp
Version: 3.2.4-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for gimp.
CVE-2026-66758[0]:
| A flaw was found in the file-fits plugin in GIMP. When processing a
| FITS image file, the plugin calculates memory allocation sizes using
| signed 32-bit integers for width and height. If a crafted file sets
| both values to large values, their product exceeds 2^31 and
| overflows, resulting in an undersized heap-based buffer allocation.
| This integer overflow issue results in a heap-based buffer overflow
| when cfitsio subsequently writes a full row of pixels in the buffer,
| causing memory corruption, potentially leading to arbitrary code
| execution or a denial of service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-66758
https://www.cve.org/CVERecord?id=CVE-2026-66758
[1] https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
[2]
https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9
Please adjust the affected versions in the BTS as needed.
Regards,
salvtore
--- End Message ---
--- Begin Message ---
Source: gimp
Source-Version: 3.0.4-3+deb13u10
Done: Moritz Mühlenhoff <[email protected]>
We believe that the bug you reported is fixed in the latest version of
gimp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Moritz Mühlenhoff <[email protected]> (supplier of updated gimp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 21 Aug 2026 21:03:47 +0200
Source: gimp
Architecture: source
Version: 3.0.4-3+deb13u10
Distribution: trixie-security
Urgency: medium
Maintainer: Debian GNOME Maintainers
<[email protected]>
Changed-By: Moritz Mühlenhoff <[email protected]>
Closes: 1141415 1142991 1142992 1144526 1144528
Changes:
gimp (3.0.4-3+deb13u10) trixie-security; urgency=medium
.
* CVE-2026-18301
* CVE-2026-18302
* CVE-2026-18303
* CVE-2026-18304
* CVE-2026-18305
* CVE-2026-18306
* CVE-2026-18307
* CVE-2026-18308
* CVE-2026-42170
* CVE-2026-58379 (Closes: #1141415)
* CVE-2026-58380
* CVE-2026-58381
* CVE-2026-58384
* CVE-2026-59088 (Closes: #1144528)
* CVE-2026-59090 (Closes: #1144526)
* CVE-2026-66758 (Closes: #1142991)
* CVE-2026-66759 (Closes: #1142992)
Checksums-Sha1:
cd972aeb0d9f685365e363b9133057fa46a63da7 3927 gimp_3.0.4-3+deb13u10.dsc
4782d6526290f44b2a1802e2c3d531b1351cf2b5 83164
gimp_3.0.4-3+deb13u10.debian.tar.xz
43b2f38be681de40ed553268e23e15962c188529 24914
gimp_3.0.4-3+deb13u10_amd64.buildinfo
Checksums-Sha256:
911db979b8c250dc3d3bec20b73a60da9bfffd79cb6bead06445d710d5c3be5a 3927
gimp_3.0.4-3+deb13u10.dsc
36b090a0a9d0b15e1ad61ee6b92ee354f746883b21ac91912ec8b36d4cad512f 83164
gimp_3.0.4-3+deb13u10.debian.tar.xz
181c27e40d9ab7a72f8b6bedf0cfc3845bd5570c47c2cbf45863b68f32fdf586 24914
gimp_3.0.4-3+deb13u10_amd64.buildinfo
Files:
ce3bc966c3356a389d10fe57085c3864 3927 graphics optional
gimp_3.0.4-3+deb13u10.dsc
c7d020d9882dedc5fec8088948c456c4 83164 graphics optional
gimp_3.0.4-3+deb13u10.debian.tar.xz
acc50a47cc627b16bd7d001dfd6bfe89 24914 graphics optional
gimp_3.0.4-3+deb13u10_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqIyDcACgkQEMKTtsN8
TjYBPg//cezZF/XP9kXguhrSh7o6ODerTuaQD1rM2ocYgr7V5L1xZaWfHBkBYlzf
85w+NVvlP0Ai/jgf6yNtIjppFAeBPFAFS7wE61wUHi3LzqpIZMDiUZ+6Rx/MvKgW
P++3HYU2TX9Gv+csgsknODTOxbUviimCwT4LXHJM/rmsbeCK5sP3ALpYD9u+330f
ZeB5NgAiKDaR4SXdko76L/lO7/OnYxnNb8n8nQRJh2w4+yMK/HTu/U1sRFvSNiWD
7U5oc56kTvn1WLYaDA8SOxoe4PHxxOBbGXwSN8cLCLzgsCI/Qrss5jiLciALDwbY
0Oz8AmqcxNeTdkyItBRgrj/rQDo8H9LOonifY7yoMHLZ+JObviTzA6RoxJHZsN33
kVUp8YNSL0Acz2ixcKo8cA/JH2oN9U81omirCsb65XTsBMcALThBlTXw1v0M2HAg
UZV668ioBI46/xLbR4xP/da3qv5fobtYdPI9e00iFPgcGG8tWvwXXgMMkcjNgBNV
7BBFyspJe+o+eJXjHwb2d5Er0CRVUqqxBiT1aDK2aAhwDn6HxXYxNBMjUYC45hwc
J+qO693lX1I2QqxZiTsnZ1ChGDVsQ+tgPDAhik3veRCt8FfuiV3R3aidozPt/m4c
rlswUB7Py5IwciZ0a5nZelbsy/GHn2pEVr7QH/941KycBR3icKA=
=TaLC
-----END PGP SIGNATURE-----
pgpjSOVF3rEPv.pgp
Description: PGP signature
--- End Message ---