CVE-2026-59087

NameCVE-2026-59087
DescriptionA flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144529

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gimp (PTS)bullseye2.10.22-4+deb11u2fixed
bullseye (security)2.10.22-4+deb11u8fixed
bookworm, bookworm (security)2.10.34-1+deb12u10fixed
trixie3.0.4-3+deb13u9fixed
trixie (security)3.0.4-3+deb13u10fixed
forky, sid3.2.4-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gimpsourcebullseye(not affected)
gimpsourcebookworm(not affected)
gimpsourcetrixie(not affected)
gimpsource(unstable)(unfixed)1144529

Notes

[trixie] - gimp <not-affected> (Vulnerable code not present)
[bookworm] - gimp <not-affected> (Vulnerable code not present)
[bullseye] - gimp <not-affected> (Vulnerable code not present)
https://gitlab.gnome.org/GNOME/gimp/-/work_items/16491
Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/bb36034bedb06305402ce836129efe8c8d4ad41d

Search for package or bug name: Reporting problems