-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:16:47 +0100 Source: gimp Binary: gimp-data libgimp-3.0-doc Architecture: all Version: 3.0.4-3+deb13u6 Distribution: trixie-security Urgency: high Maintainer: all Build Daemon (x86-csail-02) Changed-By: Salvatore Bonaccorso Description: gimp-data - Data files for GIMP libgimp-3.0-doc - Developers' Documentation for the GIMP library Closes: 1127838 1127841 1127842 Changes: gimp (3.0.4-3+deb13u6) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: fc13a42061101d5e32278933d91ae511b0ea28af 12274676 gimp-data_3.0.4-3+deb13u6_all.deb ea5e2a239a0294462c8fec29bd0a51f908843dfe 21824 gimp_3.0.4-3+deb13u6_all-buildd.buildinfo a6fc1ed41dc2ced2fb0f1f2e7d0791f5a356833e 1067776 libgimp-3.0-doc_3.0.4-3+deb13u6_all.deb Checksums-Sha256: b8e8e07e6a1ee581275a023a3220ae79241c317b4f3646a69b98af90cb7962de 12274676 gimp-data_3.0.4-3+deb13u6_all.deb 090e314f5c11f5cf7989bb31b4ad38c57ce467c8f8ebf39eaa06bfbba9d269e5 21824 gimp_3.0.4-3+deb13u6_all-buildd.buildinfo dcfec28410d2977543ef16ffda6a27545f17919c5846a31b071afe5aca1c35f9 1067776 libgimp-3.0-doc_3.0.4-3+deb13u6_all.deb Files: 134429357c48741920ed97b96d81f080 12274676 graphics optional gimp-data_3.0.4-3+deb13u6_all.deb 0d4da8bc6d29513095708ff47de759de 21824 graphics optional gimp_3.0.4-3+deb13u6_all-buildd.buildinfo cb4481082fa125b855e522c5fdc650fb 1067776 doc optional libgimp-3.0-doc_3.0.4-3+deb13u6_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEELusn8jY95Sf7obGlx30Wh8LXl/YFAmmTad8ACgkQx30Wh8LX l/bDng/+N0KjUue1opW1xPn8fcTCnQGXByn5O78Vw+Lr6M6NzO1kOCNIWWicCa6M JOUUMRJkSGXuzI01SZbhVZrdrB+HbxOKfbVqSNap4fF1feugFXljTMzelO0EBcVS Z/PoXR9qkrALFNfH3CI2BuKq9VOq/oHnhtGefiJExgvWszjcvRlaTopeDSeNmZsY l6cYPnaRhqdX11v+E83+XFCJzqr82tm2AwoqyLMHqSkBpKgzJz6SmmG5ZT/zFfoX QoNC8YZIyMX/O4dRXmY4pbM2I1P90Zt9NqNlaMxb4nw4MlW+f+TRUltLXK7GCUMY UFP3KZyJ3RoRocVzAzZdIiMdK8MfW2zC5tLvrA1lVXG66bNhrw0B/Z6u4/Pt/JY4 nEnxvtRh30QzK9pQD7erZEXjMZTmzp1QIzzdHaQlYiEe8V4inha5Q/16dzFWjh6B k9UbElUU8g1tMIodd9KjpI8WxJsAj1AMT8TTHB9bi171HZ6y5JgtJn/4Z5LOjw3J ubRR48ISMS8qSB8nz+6iJ6G0smWg5tdAbnWMOgGEUx9dDTWjj0fCKpjOZ5qxgcfl ElkUgooDmGX1zIwR1snQAlH8e2xZy1B9sgbYiQe7twGzodiUGBqX3PKIpBOfrCOU Px/UpqXYVCBWSgJcHdpCubF1uWA/xmcU9SFnNWdGGZg2iwA6h9E= =g4mt -----END PGP SIGNATURE-----