-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:16:47 +0100 Source: gimp Binary: gimp gimp-dbgsym gir1.2-gimp-3.0 libgimp-3.0-0 libgimp-3.0-0-dbgsym libgimp-3.0-bin libgimp-3.0-bin-dbgsym libgimp-3.0-dev Architecture: ppc64el Version: 3.0.4-3+deb13u6 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Salvatore Bonaccorso Description: gimp - GNU Image Manipulation Program gir1.2-gimp-3.0 - Introspection data for the GIMP library libgimp-3.0-0 - Libraries for the GNU Image Manipulation Program libgimp-3.0-bin - Development binaries for the GIMP library libgimp-3.0-dev - Headers and other files for compiling plugins for GIMP Closes: 1127838 1127841 1127842 Changes: gimp (3.0.4-3+deb13u6) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: 0116fac2658d3b0b73cb25e9fa22aafe622dac75 16578556 gimp-dbgsym_3.0.4-3+deb13u6_ppc64el.deb 2e502707e56c0b347a2ed567b7f181635a68387e 23305 gimp_3.0.4-3+deb13u6_ppc64el-buildd.buildinfo bd452d97681cd5667c1fedbf0df39c620a7c8fbb 7128384 gimp_3.0.4-3+deb13u6_ppc64el.deb e9ff9fd1029d5098a1c202090a24869c29bde82f 93440 gir1.2-gimp-3.0_3.0.4-3+deb13u6_ppc64el.deb d4eff4fae887850e4b4966d04bc9f25aabdf9ea3 2064704 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_ppc64el.deb 6d3b180df6d5a10da14fe641d15c19bee6b3f2ba 1065956 libgimp-3.0-0_3.0.4-3+deb13u6_ppc64el.deb 74a10aadd4c600866e30ba86bbb131b4a92688d6 18704 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_ppc64el.deb d1869988ba918e824da386e438dbea9b5ac7512a 33164 libgimp-3.0-bin_3.0.4-3+deb13u6_ppc64el.deb 4c2c42ba5f9741c17b3cfd3a7cab81ce9af18df4 360148 libgimp-3.0-dev_3.0.4-3+deb13u6_ppc64el.deb Checksums-Sha256: 0d707c093ef3610b278a37635dd4cba956e8948468a75437b3a79df6fed4ec7c 16578556 gimp-dbgsym_3.0.4-3+deb13u6_ppc64el.deb fc7e70d783c1c96f66565cad09e854325deb0a4e047b1ed23290c159fa9dac25 23305 gimp_3.0.4-3+deb13u6_ppc64el-buildd.buildinfo cb61405d610e484c7c64347883a6290a5d48cbcc33a400ef582eca7613fe72fa 7128384 gimp_3.0.4-3+deb13u6_ppc64el.deb ab18a5ba68e011853a8683e60965a75ecf7dadb80a081ecb158d517d12e03c71 93440 gir1.2-gimp-3.0_3.0.4-3+deb13u6_ppc64el.deb 1ea404e1d25ca56c352f563e1afd4cae1bfe478f24fec93affd4ec0aca3602a1 2064704 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_ppc64el.deb 3a14cf05ff8576760d110bff46e2bbbe0c25d8c4346f2c6e1bcbbbb04e628c87 1065956 libgimp-3.0-0_3.0.4-3+deb13u6_ppc64el.deb 90113ed6852b285a794c344776a70a1073b3ca04ef5ebdb464faf37ed63df851 18704 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_ppc64el.deb 254077604bafeb99c5f341042bbb20179f1925412d981f11cb509f787b7ab6fe 33164 libgimp-3.0-bin_3.0.4-3+deb13u6_ppc64el.deb a8651279e7d9392beeade2d5fe63b1b424f4905d4e6bf656d24fc2c8fc6a8755 360148 libgimp-3.0-dev_3.0.4-3+deb13u6_ppc64el.deb Files: 81f416d9acbbf2e448ec442e34e94671 16578556 debug optional gimp-dbgsym_3.0.4-3+deb13u6_ppc64el.deb b2f7d67de2ed2f148a9b0a9157089650 23305 graphics optional gimp_3.0.4-3+deb13u6_ppc64el-buildd.buildinfo 1db04172d1d44d5d6c0e8f800cbdc86b 7128384 graphics optional gimp_3.0.4-3+deb13u6_ppc64el.deb 70e685bcc9037d337b88d36e548afa02 93440 introspection optional gir1.2-gimp-3.0_3.0.4-3+deb13u6_ppc64el.deb 630235dede83993368aa508a700d4ac3 2064704 debug optional libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_ppc64el.deb c22a59487b0692860831479a2d7c3fab 1065956 libs optional libgimp-3.0-0_3.0.4-3+deb13u6_ppc64el.deb bd90dedb9768b0979abac42babce9948 18704 debug optional libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_ppc64el.deb fa55419a8f37d1d4e1575109138deb32 33164 libdevel optional libgimp-3.0-bin_3.0.4-3+deb13u6_ppc64el.deb e1313661b37aaa2032943113e5e890b0 360148 libdevel optional libgimp-3.0-dev_3.0.4-3+deb13u6_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmmTaj4ACgkQ2FRWNm40 e2YIYBAAjjyJ/TrLNKA2Aht+3Se/OnEMPUYsCA3SvemGQnKxmW1naNf0g9WcBhUJ haQX3weQ+dqSVU72aGUJfxHHze4Rn6Hk3YoOXgZbAgespgTk5uloP3Qxv1UJO6cs +T0+gjzaqG1T/O4nJQNukfthe8M8Bca7a5bQq0A/GCWTM1WRiM9+E3suqk8nbtun iqloL0GqbwgTD96rq0liWhymfIsnYtTcXzj5l029OtvKX22ocnXiC5MdG5qKhIyG 80FtsZYCNninQ+UIWyVp7pDK2KArYTQFrhfAjrQaS9VR1RaiRWPAsxmSKEB9hUSk XYvk/iP3iQEiMladqtLoDGIpmDtLy5CEQEtsKsqOmKUpzAQ+NVkEY985QJbzBomr Wc08Aqp0H+RF04dMXY5/rpL1q9+uy6StK84G+CtOess5SGmNLYqVBC2QUIH+TBIn y9XI3KZyMvIuav+T/EbYZsoVprOli7mjaG+NwuALJx0VZRVuWoHMos/s3IImdhdE /UX6LG2Sh+G49ZyRY3QmUqkWeJVKzLwEngSLyYsM/2uEQnWPzevtwSNe1D78wva3 wmGRnDihKKsOXHk4b3oeH9cmfth7lepKSBcFKpgt1p/ls2902tN1G7xTJY7UG1VT 3kTDXo/kg8TcUa0N2gSyf+EDjMgGRXlBzb5uBJiEhDvKpaGaqWg= =mAXs -----END PGP SIGNATURE-----