CVE-2026-59088

NameCVE-2026-59088
DescriptionA flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, leading to the application crashing and resulting in a denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6470-1
Debian Bugs1144528

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gimp (PTS)bullseye2.10.22-4+deb11u2vulnerable
bullseye (security)2.10.22-4+deb11u8vulnerable
bookworm, bookworm (security)2.10.34-1+deb12u10vulnerable
trixie3.0.4-3+deb13u9vulnerable
trixie (security)3.0.4-3+deb13u10fixed
forky, sid3.2.4-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gimpsourcetrixie3.0.4-3+deb13u10DSA-6470-1
gimpsource(unstable)(unfixed)1144528

Notes

https://gitlab.gnome.org/GNOME/gimp/-/work_items/16492
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/1db4690bde3a349df046f85a4ee9a71af8492216

Search for package or bug name: Reporting problems