-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:16:47 +0100 Source: gimp Binary: gimp gimp-dbgsym gir1.2-gimp-3.0 libgimp-3.0-0 libgimp-3.0-0-dbgsym libgimp-3.0-bin libgimp-3.0-bin-dbgsym libgimp-3.0-dev Architecture: armhf Version: 3.0.4-3+deb13u6 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Salvatore Bonaccorso Description: gimp - GNU Image Manipulation Program gir1.2-gimp-3.0 - Introspection data for the GIMP library libgimp-3.0-0 - Libraries for the GNU Image Manipulation Program libgimp-3.0-bin - Development binaries for the GIMP library libgimp-3.0-dev - Headers and other files for compiling plugins for GIMP Closes: 1127838 1127841 1127842 Changes: gimp (3.0.4-3+deb13u6) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: 7ec921b917ff954426eef1619af9d8834544d8e6 16266484 gimp-dbgsym_3.0.4-3+deb13u6_armhf.deb 6fc5447f3ca36379d70fccb023e9924ae0e58583 23106 gimp_3.0.4-3+deb13u6_armhf-buildd.buildinfo 15bae093a4c04c841fab67d8d5804e4bf48b5852 5947476 gimp_3.0.4-3+deb13u6_armhf.deb a6232530429920332c9c1ed15b96f5e778b71d44 93244 gir1.2-gimp-3.0_3.0.4-3+deb13u6_armhf.deb 331c79c93a419aad78b46fae02538046728a8ad7 2015344 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armhf.deb 557ea820b769d9f5fb8b33223a7d540c367698a7 950044 libgimp-3.0-0_3.0.4-3+deb13u6_armhf.deb 61b66ddf34762d2e309cb39e1d2310564f524f4b 18480 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armhf.deb ff2dda434ff18d057824787712f1216012f9aba9 31448 libgimp-3.0-bin_3.0.4-3+deb13u6_armhf.deb acb85e881b890f1bd367be871c6b49708c1522ef 360136 libgimp-3.0-dev_3.0.4-3+deb13u6_armhf.deb Checksums-Sha256: d6f7b5d7ae8eec16cac88d4f24237563f9d93f9f285a2f4379051c15f392f600 16266484 gimp-dbgsym_3.0.4-3+deb13u6_armhf.deb f03160804231a220c1e20c28da04645713a406a1ad9e31232ebac6d24db75746 23106 gimp_3.0.4-3+deb13u6_armhf-buildd.buildinfo 593c93837e7f7ae9267d12e72569dae9923bc5e56e139b2fe40d9c6bc2a56ee7 5947476 gimp_3.0.4-3+deb13u6_armhf.deb 987fdcb604f90998650c1e3875d62c1d16206e5f60c072a10b09a168d4f43371 93244 gir1.2-gimp-3.0_3.0.4-3+deb13u6_armhf.deb 08b4700f63fc866650c35b7b162f4014e6e7bd77d359459eb5a83de3a16398f9 2015344 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armhf.deb 6e89a682c6d0132efa1ecc703e58f7075e9161a820e782ec2c525123ab2db512 950044 libgimp-3.0-0_3.0.4-3+deb13u6_armhf.deb 0ce4884860edfaa2653780c7b9cea105b05c2c40b545269a4470f4b91b207261 18480 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armhf.deb 83cbb30c988b551ecd9b019160198019553191c149151c07ce81993cb6000bb8 31448 libgimp-3.0-bin_3.0.4-3+deb13u6_armhf.deb 59f3659721c8b7f9c44c90e88059174b52583a12c1467762f4d8d6d8b18c019e 360136 libgimp-3.0-dev_3.0.4-3+deb13u6_armhf.deb Files: f65912bfd2b74b0903ac7269a5c91d50 16266484 debug optional gimp-dbgsym_3.0.4-3+deb13u6_armhf.deb 793e3c00564e40e0bfd1e5ba7375dd09 23106 graphics optional gimp_3.0.4-3+deb13u6_armhf-buildd.buildinfo d01c480494632f1b6c4d6af32cd48ab5 5947476 graphics optional gimp_3.0.4-3+deb13u6_armhf.deb a601c97a1bef62c768eabe2c7dc749e0 93244 introspection optional gir1.2-gimp-3.0_3.0.4-3+deb13u6_armhf.deb 745d0dfcd333cdf42836b9cde0f92ec6 2015344 debug optional libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armhf.deb 9ad7d9cafc3c432bf1835a39318d01e5 950044 libs optional libgimp-3.0-0_3.0.4-3+deb13u6_armhf.deb 407e4a977a8aee12a7d7748f5831cb7e 18480 debug optional libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armhf.deb 4e9b39dd1af05bf6afeab7c5a45dd0f0 31448 libdevel optional libgimp-3.0-bin_3.0.4-3+deb13u6_armhf.deb 996ba4e796b7cba6ae5b8de07dcd19c2 360136 libdevel optional libgimp-3.0-dev_3.0.4-3+deb13u6_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmmTakAACgkQLRECdjCZ QkeWQQ/+KuFZUFnbrQoQaGM6WZWpm7sgY+UeyMuZMbUUJ3cOWFiRQZy7RSzDQeU0 VdU0FoGH+KaDihyqnTV02GQC7+0x8CMgzSp+QNOgmGAaSvqhJHWRxrT9/8wjTvln A4pRfSlg0UXo31H3W7Uo/jQzx0FTzG8IENyT3BkXWnRqutCvz39b4NQN3pw3WEC5 QWPv/Z5Nc/mLLoErppi+fiOX3Ne7mGwDfURHWv+3NRz+6IxWH4Vwa3iLJ+s0rjYJ tL9TI3zMReGWGwi6GsCSNsFHmMZ0ZN5jGV3XtXNdWcW0rMRh1Jq6T82PxxuEKtcL Q6qmoPZCD9U0Mi/AlMWKEnV2x1iRraUQcNZYDXUAz5OcmIoH3lgfAT4yFn0MsUvn r5/loTUYKDDSbRtmMLmlZAcQIb/Vl5mvJcLJUY0qEFkDbZcaLLvJiRY+Wqq3mkII ijVConMNI8IC4sviUXrKxs77de/bpxWmvrRfN1IePoE5G1zHRUCVivcivpU7o4VT l5BilUut23GQZrb9HqGvyKRkdDR0UE52jk2kZVZpj18hEanzQ8L+zJEiVYJVNvVI MsM+XoDVDyDg76n334bpF3u6LNMFE4mS5T7yuy6cZhydrDrCUoFA0LPs+NXDaKYM xUdlFarNQcZPtXNiSz4y5Rvjpmr1t3+NgEnbyu79Pamcys6yACY= =wzoy -----END PGP SIGNATURE-----