File _patchinfo of Package patchinfo.42671
<patchinfo incident="42671"> <issue tracker="cve" id="2026-2271"/> <issue tracker="cve" id="2026-2239"/> <issue tracker="cve" id="2026-2272"/> <issue tracker="bnc" id="1258000">VUL-0: CVE-2026-2272: gimp: integer overflow in ICO file handling can lead to a heap buffer overflow</issue> <issue tracker="bnc" id="1257999">VUL-0: CVE-2026-2271: gimp: integer overflow in the PSP file parser can lead to a heap buffer overflow</issue> <issue tracker="bnc" id="1257959">VUL-0: CVE-2026-2239: gimp: missing null terminator when processing a specially crafted PSD file can lead to a heap buffer overflow and an application crash</issue> <packager>mgorse</packager> <rating>important</rating> <category>security</category> <summary>Security update for gimp</summary> <description>This update for gimp fixes the following issues: - CVE-2026-2272: integer overflow in ICO file handling can lead to a heap buffer overflow (bsc#1258000). - CVE-2026-2271: integer overflow in the PSP file parser can lead to a heap buffer overflow (bsc#1257999). - CVE-2026-2239: missing null terminator when processing a specially crafted PSD file can lead to a heap buffer overflow and an application crash (bsc#1257959). </description> </patchinfo>