Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gimp for openSUSE:Factory checked in at 2026-09-24 22:55:19 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gimp (Old) and /work/SRC/openSUSE:Factory/.gimp.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gimp" Thu Sep 24 22:55:19 2026 rev:173 rq:1379776 version:3.2.6 Changes: -------- --- /work/SRC/openSUSE:Factory/gimp/gimp.changes 2026-09-14 16:20:09.730970179 +0200 +++ /work/SRC/openSUSE:Factory/.gimp.new.383539/gimp.changes 2026-09-24 22:55:24.168052316 +0200 @@ -1,0 +2,7 @@ +Wed Sep 16 00:41:47 UTC 2026 - Alynx Zhou <[email protected]> + +- Add gimp-fix-invalid-XWD-guards.patch: Fix invalid guards for XWD + parameters which is used to fix CVE-2026-80101. + (glgo#GNOME/gimp!3007, bsc#1279839) + +------------------------------------------------------------------- New: ---- gimp-fix-invalid-XWD-guards.patch ----------(New B)---------- New: - Add gimp-fix-invalid-XWD-guards.patch: Fix invalid guards for XWD parameters which is used to fix CVE-2026-80101. ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gimp.spec ++++++ --- /var/tmp/diff_new_pack.FqFlBq/_old 2026-09-24 22:55:26.138134646 +0200 +++ /var/tmp/diff_new_pack.FqFlBq/_new 2026-09-24 22:55:26.143134855 +0200 @@ -102,6 +102,8 @@ Patch2: gimp-2.99.19-external-help-browser.patch # PATCH-FIX-OPENSUSE disable update checks Patch3: gimp-2.99.19-no-phone-home-default.patch +# PATCH-FIX-UPSTREAM gimp-fix-invalid-XWD-guards.patch glgo#GNOME/gimp!3007, bsc#1279839 [email protected] -- Fix invalid guards for XWD parameters +Patch4: gimp-fix-invalid-XWD-guards.patch %if %{with debug_in_build_gimp} BuildRequires: gdb %endif ++++++ gimp-fix-invalid-XWD-guards.patch ++++++ >From 40e5a59a19e143e5535af27eb62ef93e169a0174 Mon Sep 17 00:00:00 2001 From: Alynx Zhou <[email protected]> Date: Tue, 15 Sep 2026 10:17:08 +0800 Subject: [PATCH] plug-ins: Fix invalid guards for XWD parameters `bpp` is always 1 for those checks, and integer divide `1 / 8` leads into an unintentional zero which always skips the check, use float instead. And use correct value instead of mismatched one. Related to !2915 --- plug-ins/common/file-xwd.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/plug-ins/common/file-xwd.c b/plug-ins/common/file-xwd.c index 4b69c965df4..b4cd6708222 100644 --- a/plug-ins/common/file-xwd.c +++ b/plug-ins/common/file-xwd.c @@ -1390,10 +1390,10 @@ load_xwd_f2_d1_b1 (GFile *file, data = g_malloc (tile_height * width); allocation = xwdhdr->l_bytes_per_line + 8; - if (ceil (width * (bpp / 8)) > allocation) + if (ceil (width * (bpp / 8.0f)) > allocation) { g_warning ("XWD: Mismatch between width and bytes per line"); - allocation = ceil (width * (bpp / 8)); + allocation = ceil (width * (bpp / 8.0f)); } scanline = g_new0 (guchar, allocation); @@ -2294,12 +2294,12 @@ load_xwd_f1_d24_b1 (GFile *file, bpp = xwdhdr->l_bits_per_pixel; allocation = xwdhdr->l_bytes_per_line; - if (ceil (width * (bpp / 8)) > allocation) + if (ceil (width * (bpp / 8.0f)) > allocation) { g_warning ("XWD: Mismatch between width and bytes per line"); - allocation = ceil (width * (bpp / 8)); + allocation = ceil (width * (bpp / 8.0f)); } - xwddata = g_try_malloc (xwdhdr->l_bytes_per_line); + xwddata = g_try_malloc (allocation); if (xwddata == NULL) return NULL; -- GitLab
