-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:16:47 +0100 Source: gimp Binary: gimp gimp-dbgsym gir1.2-gimp-3.0 libgimp-3.0-0 libgimp-3.0-0-dbgsym libgimp-3.0-bin libgimp-3.0-bin-dbgsym libgimp-3.0-dev Architecture: armel Version: 3.0.4-3+deb13u6 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Salvatore Bonaccorso Description: gimp - GNU Image Manipulation Program gir1.2-gimp-3.0 - Introspection data for the GIMP library libgimp-3.0-0 - Libraries for the GNU Image Manipulation Program libgimp-3.0-bin - Development binaries for the GIMP library libgimp-3.0-dev - Headers and other files for compiling plugins for GIMP Closes: 1127838 1127841 1127842 Changes: gimp (3.0.4-3+deb13u6) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: bff6359148fa2d18296dda913b65ea42e4450685 16171112 gimp-dbgsym_3.0.4-3+deb13u6_armel.deb 81e72f7f60bfe62847068b6358d3671f0fdea495 23119 gimp_3.0.4-3+deb13u6_armel-buildd.buildinfo f699103df38627bc72d23f1317a02d9557be000c 5960424 gimp_3.0.4-3+deb13u6_armel.deb fe2038828523bd370491ef6133ba0bdeacaf9f1d 93388 gir1.2-gimp-3.0_3.0.4-3+deb13u6_armel.deb 78768b468f30103a1cb9c276baa0e95331930954 1985504 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armel.deb f1ff978d2b7d264d7bfd189a1f39282ba4befe81 952336 libgimp-3.0-0_3.0.4-3+deb13u6_armel.deb 88418a9b8f8e7717ce56ed39166882843ee816a6 18404 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armel.deb dcc948edaec4fe3327725354064c93199df97239 31476 libgimp-3.0-bin_3.0.4-3+deb13u6_armel.deb 2f2db7cf1c739aa28395d3ae181eb8b7445bb609 360112 libgimp-3.0-dev_3.0.4-3+deb13u6_armel.deb Checksums-Sha256: 1943d03232b38d017ec173b29a0be0206b2186f661ecdde959c7e88a5bd4e8dd 16171112 gimp-dbgsym_3.0.4-3+deb13u6_armel.deb 477b6fa00d322224f58826d0e53223545651170d72f9dbfb357566eabd40a9d3 23119 gimp_3.0.4-3+deb13u6_armel-buildd.buildinfo 7e54410ac61654ac318917eee6e32afe074095751bfd251e87165f25308fa070 5960424 gimp_3.0.4-3+deb13u6_armel.deb 53d48ea7a029ba44d746bacdb0debcb997a666f3ea443d3d7a64b92028866660 93388 gir1.2-gimp-3.0_3.0.4-3+deb13u6_armel.deb f27357dcb9230258bc98cfc6102f5adfa803f171a701a995c007d29c05c27228 1985504 libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armel.deb c5297698f3e83499db0842acd003b19cbcb6aca0fb29166b29e0c998be77ebe9 952336 libgimp-3.0-0_3.0.4-3+deb13u6_armel.deb 78c6fcb3dbd8f3240b62591baa2c714b9717ec4ad1f15751880fa4508606058c 18404 libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armel.deb c14cc3e7fdb696fee5396206eb503c2b593c206c252f8b533ae63e4398604e0f 31476 libgimp-3.0-bin_3.0.4-3+deb13u6_armel.deb 119414db45d1ea016e8334860d1c4c76d929c54846b4a6d77c7a40e8fe862bb3 360112 libgimp-3.0-dev_3.0.4-3+deb13u6_armel.deb Files: 8923499e88ee5e147c782bb55f29237e 16171112 debug optional gimp-dbgsym_3.0.4-3+deb13u6_armel.deb 37e7d59e974247c9c6b38b868d853453 23119 graphics optional gimp_3.0.4-3+deb13u6_armel-buildd.buildinfo 46bde8b969d754dcbfcc9a65b0ec2e4f 5960424 graphics optional gimp_3.0.4-3+deb13u6_armel.deb 11d0a316943bee88de7a5d83c9544624 93388 introspection optional gir1.2-gimp-3.0_3.0.4-3+deb13u6_armel.deb 516d3126d2699dd9a51e97cf4c84eafd 1985504 debug optional libgimp-3.0-0-dbgsym_3.0.4-3+deb13u6_armel.deb e8cce2cfab874cb73027abb810730e00 952336 libs optional libgimp-3.0-0_3.0.4-3+deb13u6_armel.deb 88283a384d797669b23ae26efc7c55d5 18404 debug optional libgimp-3.0-bin-dbgsym_3.0.4-3+deb13u6_armel.deb cdd3c7c61e63fc4f41d03058710e858e 31476 libdevel optional libgimp-3.0-bin_3.0.4-3+deb13u6_armel.deb 38c38c42a20f0575b20ad710dabdc77c 360112 libdevel optional libgimp-3.0-dev_3.0.4-3+deb13u6_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENsdrABvTD8MQ0UffVza3l394K2AFAmmTa38ACgkQVza3l394 K2CndBAAoAB17IvgB1ee89NHcdWIYphBEUBZi9SWtjlJZgasH9VUNpaPOmY3ICoj uSNVS+l8Fe5efFL4zoIIKTPBRaXsrlYMOBS3iOEKAGYUl9wy281jbEfi6jkgvGnW nSbvavIxjPfi9b5yk8XW1kee1T3Rgp28pUe7KxXdaGTtJORS1NKpj0xl6j6rSQBY sznn6WogPy9NzIXAZGF0dxohGthHA+5KLfpPdvIFLdPHWA4GDLpg24lrX1ISaZZO 2662aUIHtazkNw2o2VjV5DTZtmAROm9ZJfinUGdOwrMvPUjs9424ORWcNFaceMQU 6ZkXAdv7K3+RMrowprUco24BvERqKsUfl1Qm5MQ1L9BM888PZ5vCfrmV34wci0pV mNVbIQhmrNWgR4K2uc/MFIh+vZE9zJ5pMIQhoe6Kr/crLITG+pwtZNmXpX3vrZyv hAWDcHAm6u4dn4cfB6wgC2c5d/vz3Zt9XPTfrlrVJy/Kn3QA35haPRKyQqS1KBCP e0S6u5BJgw9/HYMrggkbBEkYGopyaD+TyYD9spTig2ru83F+X0e5Ibv3c7GVPMJw btQ+JcZ9ZDFQ55P68Slwfh4guNZVGe6nH/saXEOahvMaA83g2vAVqNQ+9jvK9u01 wyPX3tEQWiYtnvzFR9o3eFBTMpTl+9q6yaTeBYdBRpwR1j0eDS0= =uOJz -----END PGP SIGNATURE-----