CVE-2025-10921

NameCVE-2025-10921
DescriptionGIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6018-1
Debian Bugs1116470

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gegl (PTS)bullseye1:0.4.26-2vulnerable
bookworm1:0.4.42-2vulnerable
bookworm (security)1:0.4.42-2+deb12u1fixed
trixie1:0.4.62-2vulnerable
trixie (security)1:0.4.62-2+deb13u1fixed
forky1:0.4.62-3vulnerable
sid1:0.4.62-3.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
geglsourcebookworm1:0.4.42-2+deb12u1DSA-6018-1
geglsourcetrixie1:0.4.62-2+deb13u1DSA-6018-1
geglsource(unstable)1:0.4.62-3.11116470

Notes

https://gitlab.gnome.org/GNOME/gegl/-/issues/430
Fixed by: https://gitlab.gnome.org/GNOME/gegl/-/commit/0e68b7471dabf2800d780819c19bd5e6462f565f

Search for package or bug name: Reporting problems