-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Feb 2026 17:20:06 +0100 Source: gimp Binary: gimp gimp-dbgsym libgimp2.0 libgimp2.0-dbgsym libgimp2.0-dev libgimp2.0-dev-dbgsym Architecture: ppc64el Version: 2.10.34-1+deb12u8 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Salvatore Bonaccorso Description: gimp - GNU Image Manipulation Program libgimp2.0 - Libraries for the GNU Image Manipulation Program libgimp2.0-dev - Headers and other files for compiling plugins for GIMP Closes: 1127838 1127841 1127842 Changes: gimp (2.10.34-1+deb12u8) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * plug-ins: fix PSD loader: heap-buffer-overflow in fread_pascal_string (CVE-2026-2239) (Closes: #1127838) * Fix PSP File Parsing Integer Overflow Leading to Heap Corruption (CVE-2026-2271) (Closes: #1127841) * plug-ins: Add overflow checks for ICO loading (CVE-2026-2272) (Closes: #1127842) * plug-ins: fix crash due to uninitialized ptr_array when loading a specially crafted PSD Checksums-Sha1: b15fffdd4f8f03d1bfb9d067a2972bdb34f73196 15930660 gimp-dbgsym_2.10.34-1+deb12u8_ppc64el.deb b38afbeb5d4137986b1e27ec5cdff684d414b767 21226 gimp_2.10.34-1+deb12u8_ppc64el-buildd.buildinfo 9550ce3d7b5d5edac801e80a17c8d7420669ff89 4604784 gimp_2.10.34-1+deb12u8_ppc64el.deb ba83a1714006181aeff16ce4e718c5ceb671d5b7 1377388 libgimp2.0-dbgsym_2.10.34-1+deb12u8_ppc64el.deb d56bffceb707669fc4694d2b621ea72654c3cb36 17272 libgimp2.0-dev-dbgsym_2.10.34-1+deb12u8_ppc64el.deb 1cfc0ac21ffd2b1c8609df4027b012e6a881e051 122392 libgimp2.0-dev_2.10.34-1+deb12u8_ppc64el.deb 17bb21aee06680f0cbb976a2595ab3a976e615a6 833588 libgimp2.0_2.10.34-1+deb12u8_ppc64el.deb Checksums-Sha256: 37c90a37084853da741d841f23cf42fd31a412cf3da84a437d44dc444d4bc6f4 15930660 gimp-dbgsym_2.10.34-1+deb12u8_ppc64el.deb 0b3223af058da4d0cae91f34d8689e44c320565a0674461e2ee43d327d1c3a8b 21226 gimp_2.10.34-1+deb12u8_ppc64el-buildd.buildinfo 9448c790a82bf75d965e9044716e469c84433834a0b09635806e55c4e9d042e8 4604784 gimp_2.10.34-1+deb12u8_ppc64el.deb ebb8e0499b942a64c6c39e9127931f6f7f59e57b2d8d397644867b77c4961aec 1377388 libgimp2.0-dbgsym_2.10.34-1+deb12u8_ppc64el.deb 91bce12b05c1fa5977130c347a38e4826a8fab5390a72656c3c2390a9d1bbdce 17272 libgimp2.0-dev-dbgsym_2.10.34-1+deb12u8_ppc64el.deb 62e27287aef904d9b732dc221e7bdb8074f829153a7ba1eadd770604c92f1d75 122392 libgimp2.0-dev_2.10.34-1+deb12u8_ppc64el.deb f7c0af6dacf01e3b7437c2b89478b6fa5d5b7c88d4df4d2eda27d502fcb713ae 833588 libgimp2.0_2.10.34-1+deb12u8_ppc64el.deb Files: 23251fa5417dd8da520d49a6c2d9dc9e 15930660 debug optional gimp-dbgsym_2.10.34-1+deb12u8_ppc64el.deb de9b1d52d93c7bf17c704b35721bad53 21226 graphics optional gimp_2.10.34-1+deb12u8_ppc64el-buildd.buildinfo ab10b34824b35025b37a0c6954f49a06 4604784 graphics optional gimp_2.10.34-1+deb12u8_ppc64el.deb e7063b218bcec06054e24ef279b6fd25 1377388 debug optional libgimp2.0-dbgsym_2.10.34-1+deb12u8_ppc64el.deb fa114ec0f08f44aada4701f0bfe5e245 17272 debug optional libgimp2.0-dev-dbgsym_2.10.34-1+deb12u8_ppc64el.deb 2ed134f6fa2ffda65e8276b079b49371 122392 libdevel optional libgimp2.0-dev_2.10.34-1+deb12u8_ppc64el.deb 0bc24bbb0d256a34988c016be3932a7e 833588 libs optional libgimp2.0_2.10.34-1+deb12u8_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmmTeQsACgkQDNLUPhbm g7PePQ/8Ds1X/HUNmYFflN0McPWNfO0mLtl6Lq2GJ79wFA8unTDzUGgmo4a8AqyO D/bhudQDsdzx56sN5tcCp/5mn4iUubviyN6DzrJzPB7YXE3q9jREYzzxDHjklExu UzrzeE+6DoTMgXjGyZ888hSmIXcl6rYTCj/pf0xbPzGkgJwamlzgdL2u60cx1sC9 Kal/weky/jz2Odt2MuKKcjF2tBkc1SZaQSBRrF81z6KSFXynL8hBozu8iKpDlect 5dz7bTnrP46s4oyl4Xcdxzs/TrW/Dx4/OV5Y5BJsT4C7aMlhZj2oscPs4VDVOJBc QcDeS8tkpze2WqTyIRSXrh41Q+3r0VRe1LhKaz7LjO4s7YKvML7fqtSlvOFAWqrC jCt3wwbHP1+E9pXqlKxVCmNmV3Y97EglMFgpkQ2UxIBWZBZqqAxUWmt3t19l/1s3 sxjW41Fi8iUnCbkpFKAOQIGmIzjgC0gHmAH3F9RoKha/XVda+mazhFBNrWrToOlZ fL/9gO3WAGUxoj92pQwSuA3s2hzqsLXAjRDXJxyeDnvfh+8fXzmdYrtx7rvGrXbs b6whH+3JTWhD38m/GLNGqFJc5uieZO3azLj5jHZWS3aeiUAgJKyvddtvoD8L3txJ Jh+L7QIUVzLK1uoMyKeIkkrJqKDjgui5vb3izJb3Y1QUiGMdyb0= =T8ke -----END PGP SIGNATURE-----