-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:20:06 +0100 Source: gimp Binary: gimp-data libgimp2.0-doc Architecture: all Version: 2.10.34-1+deb12u8 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Salvatore Bonaccorso Description: gimp-data - Data files for GIMP libgimp2.0-doc - Developers' Documentation for the GIMP library Closes: 1127838 1127841 1127842 Changes: gimp (2.10.34-1+deb12u8) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: 80df8e4e230be78e28823bf49f529614b55f5304 14218212 gimp-data_2.10.34-1+deb12u8_all.deb 27ff0a9902306af7cc18b76891ccd8e1a428a130 20008 gimp_2.10.34-1+deb12u8_all-buildd.buildinfo dcd32797725dc0db5f3ce0870bc6d183a43cdcba 923524 libgimp2.0-doc_2.10.34-1+deb12u8_all.deb Checksums-Sha256: d9898c1750761c96ad2d97e473980e2dec9fc9e9f31518b793d76f44c5f4b3f5 14218212 gimp-data_2.10.34-1+deb12u8_all.deb 2f0de32261cbf4ec8c0c3c2c9ba5b42ff9d9d88046eccb0ebe5e649a39cbba9c 20008 gimp_2.10.34-1+deb12u8_all-buildd.buildinfo ba88e7b7ae539434fc90021b018ffc374110987caa512f5a6bda2c45fbd5966e 923524 libgimp2.0-doc_2.10.34-1+deb12u8_all.deb Files: cc29fb7cbd3f5b4b3950a406454cdb7c 14218212 graphics optional gimp-data_2.10.34-1+deb12u8_all.deb 5e08a00316a728e06486dfcc8c614274 20008 graphics optional gimp_2.10.34-1+deb12u8_all-buildd.buildinfo 5132801ba6ad5dcfdaa647e0153a17e5 923524 doc optional libgimp2.0-doc_2.10.34-1+deb12u8_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEj4Fym5GgeZdPqKhrJm69HxMTN+oFAmmTeMoACgkQJm69HxMT N+pwew//cMj4qPkCo/JRFhg8l5tJ0EPBTbYm4lYaRq+fC4MDGdhXfplgaaRW5kOV KdpMjKcvCN5EGWIY7JPz03kvDiQSAnVqvXW0qyLVam3Vtg3QnxgnkzqqLci5oq9d a9eaLNH1Yj0jCqveRh9Sv3Kt26/CHnWDMUfm3v/xOMCtVa/lGc9kl1+LQr9dfATH 2iYUwE6mr3q1F9Me5HmNqsXYIehtslF/yKgJ8QY2tdxnIv4mFa7F9tXndQzarKL9 4Vjc8lUu1wJoeN/3wxRAZjs9kDjlLTDjzZwq3F7qM0tbNxeNJ3EN6aa/fx3wW4Y1 qmlGQbXSe5+YuK3/gLuH8TY7QcEMkEzckgZfDi9zmG1JV5aldaJ+MVCjMaK6M3Bt of8mhc75twyKzQ96W3re/UeoWD7uunuPgMFn5iswBSWpPGCzxjmBGu/Oj6Ow0uBc 04jGTxrlsQTMju7xwaiU5vIERsVKdwHralhUqzX+ymA5qwLrR6vy7SoZ3UOorXo0 MB5SrWEBvg01W7CXg99GfEDVVOMdBJqrr3y7Dwz7jB1AyirYV4W6Blm3uyd6fmrX T9DNchPn42XzsM9z76zJgADnyuX6XPsziiF/iIaoeTjxtgyA1341SassNK4RQ9Zt EclCPAvoQ1/NpYarix9I4X9lXLWJ9G/Mo0Ezlzp7qepVnXEEOLY= =07BE -----END PGP SIGNATURE-----