Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gimp for openSUSE:Factory checked in at 2026-09-28 10:36:53 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gimp (Old) and /work/SRC/openSUSE:Factory/.gimp.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gimp" Mon Sep 28 10:36:53 2026 rev:174 rq:1380314 version:3.2.6 Changes: -------- --- /work/SRC/openSUSE:Factory/gimp/gimp.changes 2026-09-24 22:55:24.168052316 +0200 +++ /work/SRC/openSUSE:Factory/.gimp.new.383539/gimp.changes 2026-09-28 10:37:51.116338091 +0200 @@ -1,0 +2,36 @@ +Thu Sep 24 18:02:06 UTC 2026 - Michael Gorse <[email protected]> + +- CVE-2026-96543: out-of-bounds heap write when loading non-square + PVR images (bsc#1282539) + * gimp-CVE-2026-96543.patch +- CVE-2026-96544: integer overflow in the PVR image loader leads to + an out-of-bounds heap read (bsc#1282541) + * gimp-CVE-2026-96544.patch + * gimp-CVE-2026-96544-2.patch +- CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image + loader (bsc#1282602) + * gimp-CVE-2026-96545.patch + +------------------------------------------------------------------- +Wed Sep 23 14:49:04 UTC 2026 - Michael Gorse <[email protected]> + +- Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are + initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838 + glgo#GNOME/gimp!2997). +- CVE-2026-90948: When processing an ICO file containing an + embedded PNG image, an integer overflow can occur during the + calculation of the required buffer size (bsc#1280512) + * gimp-CVE-2026-90948.patch +- CVE-2026-90949: When processing a compressed selection channel in + gimp's PSP file loader, a heap-based buffer overflow can occur + due to a mismatch between the allocated buffer size and the + amount of data decompressed (bsc#1280513) + * gimp-CVE-2026-90949.patch +- CVE-2026-92248: When generating a thumbnail preview for a + specially crafted PSD (Photoshop Document) image file, an integer + overflow occurs during the multiplication of values from an + embedded JPEG header (bsc#1280739) + * gimp-CVE-2026-92248.patch + * gimp-CVE-2026-92248-2.patch + +------------------------------------------------------------------- New: ---- gimp-CVE-2026-90948.patch gimp-CVE-2026-90949.patch gimp-CVE-2026-92248-2.patch gimp-CVE-2026-92248.patch gimp-CVE-2026-96543.patch gimp-CVE-2026-96544-2.patch gimp-CVE-2026-96544.patch gimp-CVE-2026-96545.patch gimp-initialize-sgi-tables.patch ----------(New B)---------- New: calculation of the required buffer size (bsc#1280512) * gimp-CVE-2026-90948.patch - CVE-2026-90949: When processing a compressed selection channel in New: amount of data decompressed (bsc#1280513) * gimp-CVE-2026-90949.patch - CVE-2026-92248: When generating a thumbnail preview for a New: * gimp-CVE-2026-92248.patch * gimp-CVE-2026-92248-2.patch New: embedded JPEG header (bsc#1280739) * gimp-CVE-2026-92248.patch * gimp-CVE-2026-92248-2.patch New: PVR images (bsc#1282539) * gimp-CVE-2026-96543.patch - CVE-2026-96544: integer overflow in the PVR image loader leads to New: * gimp-CVE-2026-96544.patch * gimp-CVE-2026-96544-2.patch - CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image New: an out-of-bounds heap read (bsc#1282541) * gimp-CVE-2026-96544.patch * gimp-CVE-2026-96544-2.patch New: loader (bsc#1282602) * gimp-CVE-2026-96545.patch New: - Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838 ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gimp.spec ++++++ --- /var/tmp/diff_new_pack.j2evqn/_old 2026-09-28 10:37:52.238385011 +0200 +++ /var/tmp/diff_new_pack.j2evqn/_new 2026-09-28 10:37:52.239385053 +0200 @@ -104,6 +104,24 @@ Patch3: gimp-2.99.19-no-phone-home-default.patch # PATCH-FIX-UPSTREAM gimp-fix-invalid-XWD-guards.patch glgo#GNOME/gimp!3007, bsc#1279839 [email protected] -- Fix invalid guards for XWD parameters Patch4: gimp-fix-invalid-XWD-guards.patch +# PATCH-FIX-UPSTREAM gimp-initialize-sgi-tables.patch bsc#1279838 [email protected] -- ensure that SGI tables are initialized. +Patch5: gimp-initialize-sgi-tables.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-90948.patch bsc#1280512 [email protected] -- Stop overflow when reading PNGs in ICO. +Patch6: gimp-CVE-2026-90948.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-90949.patch bsc#1280513 [email protected] -- Use buffer size for PSP selection loading. +Patch7: gimp-CVE-2026-90949.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-92248.patch bsc#1280739 [email protected] -- Add bounds checks for PSD thumbnail. +Patch8: gimp-CVE-2026-92248.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-92248-2.patch bsc#1280739 [email protected] -- Further PSD thumbnail cleanup. +Patch9: gimp-CVE-2026-92248-2.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-96543.patch bsc#1282539 [email protected] -- Check destination offset in PVR import. +Patch10: gimp-CVE-2026-96543.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-96544.patch bsc#1282541 [email protected] -- Add bounds checks for rectangle PVRs. +Patch11: gimp-CVE-2026-96544.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-96544-2.patch bsc#1282541 [email protected] -- Fix double allocation in PVR. +Patch12: gimp-CVE-2026-96544-2.patch +# PATCH-FIX-UPSTREAM gimp-CVE-2026-96545.patch bsc#1282602 [email protected] -- Guard loading 4BPP TIM images. +Patch13: gimp-CVE-2026-96545.patch %if %{with debug_in_build_gimp} BuildRequires: gdb %endif ++++++ gimp-CVE-2026-90948.patch ++++++ >From 123d6360b8d7e2a00a9d913889ee9cdca88e2380 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Wed, 9 Sep 2026 13:42:27 +0000 Subject: [PATCH] plug-ins: Stop overflow when reading PNGs in ICO This patch converts gints used in getting the total area of a PNG loaded from an ICO file to gsize. It also uses g_size_checked_mul () to do the overflow checks instead of straight 32 bit multiplication, for better security. --- plug-ins/file-ico/ico-load.c | 62 +++++++++++++++++++++++------------- 1 file changed, 39 insertions(+), 23 deletions(-) diff --git a/plug-ins/file-ico/ico-load.c b/plug-ins/file-ico/ico-load.c index da39a3bfa6..ce531b93e6 100644 --- a/plug-ins/file-ico/ico-load.c +++ b/plug-ins/file-ico/ico-load.c @@ -274,7 +274,7 @@ static gboolean ico_read_png (FILE *fp, guint32 header, guchar *buf, - gint maxsize, + gsize maxsize, gint *width, gint *height, gint *bpp) @@ -283,6 +283,7 @@ ico_read_png (FILE *fp, png_infop info; png_uint_32 w; png_uint_32 h; + gsize total_size; gint32 bit_depth; gint32 color_type; guint32 **rows; @@ -310,15 +311,14 @@ ico_read_png (FILE *fp, png_get_IHDR (png_ptr, info, &w, &h, &bit_depth, &color_type, NULL, NULL, NULL); /* Check for overflow */ - if ((w * h * 4) < w || - (w * h * 4) < h || - (w * h * 4) < (w * h) || - (w * h * 4) > maxsize) + if (! g_size_checked_mul (&total_size, w, h) || + ! g_size_checked_mul (&total_size, total_size, 4) || + total_size > maxsize) { png_destroy_read_struct (&png_ptr, &info, NULL); return FALSE; } - D(("ico_read_png: %ix%i, %i bits, %i type\n", (gint)w, (gint)h, + D(("ico_read_png: %ix%i, %i bits, %i type\n", (gint) w, (gint) h, bit_depth, color_type)); switch (color_type) { @@ -353,13 +353,13 @@ ico_read_png (FILE *fp, break; } - *width = w; + *width = w; *height = h; - *bpp = 32; /* always expanded to 32bpp RGBA */ - rows = g_new (guint32*, h); - rows[0] = (guint32*) buf; + *bpp = 32; /* always expanded to 32bpp RGBA */ + rows = g_new (guint32 *, h); + rows[0] = (guint32 *) buf; for (i = 1; i < h; i++) - rows[i] = rows[i-1] + w; + rows[i] = rows[i - 1] + w; png_read_image (png_ptr, (png_bytepp) rows); png_destroy_read_struct (&png_ptr, &info, NULL); g_free (rows); @@ -432,7 +432,7 @@ static gboolean ico_read_icon (FILE *fp, guint32 header_size, guchar *buf, - gint maxsize, + gsize maxsize, gint *width, gint *height, gint *bpp) @@ -683,7 +683,7 @@ ico_load_layer (FILE *fp, GimpImage *image, gint32 icon_num, guchar *buf, - gint maxsize, + gsize maxsize, gint32 file_offset, gchar *layer_prefix, IcoLoadInfo *info) @@ -699,8 +699,8 @@ ico_load_layer (FILE *fp, if (first_bytes == ICO_PNG_MAGIC) { - if (!ico_read_png (fp, first_bytes, buf, maxsize, &width, &height, - &info->bpp)) + if (! ico_read_png (fp, first_bytes, buf, maxsize, &width, &height, + &info->bpp)) return NULL; } else if (first_bytes == 40) @@ -744,12 +744,13 @@ ico_load_image (GFile *file, FILE *fp; IcoFileHeader header; IcoLoadInfo *info; - gint max_width, max_height; + gsize max_width; + gsize max_height; gint i; GimpImage *image; guchar *buf; guint icon_count; - gint maxsize; + gsize maxsize; gchar *str; if (! file_offset) @@ -769,7 +770,7 @@ ico_load_image (GFile *file, if (file_offset) fseek (fp, *file_offset, SEEK_SET); - header = ico_read_init (fp); + header = ico_read_init (fp); icon_count = header.icon_count; if (!icon_count) { @@ -794,7 +795,9 @@ ico_load_image (GFile *file, if (info[i].height > max_height) max_height = info[i].height; } - if (max_width <= 0 || max_height <= 0) + if (max_width <= 0 || max_height <= 0 || + max_width > GIMP_MAX_IMAGE_SIZE || + max_height > GIMP_MAX_IMAGE_SIZE) { g_free (info); fclose (fp); @@ -804,9 +807,18 @@ ico_load_image (GFile *file, image = gimp_image_new (max_width, max_height, GIMP_RGB); - maxsize = max_width * max_height * 4; - buf = g_try_new (guchar, maxsize); - if (! buf) + if (max_width <= 0 || max_height <= 0 || + max_width > GIMP_MAX_IMAGE_SIZE || + max_height > GIMP_MAX_IMAGE_SIZE) + { + g_free (info); + fclose (fp); + return NULL; + } + + if (! g_size_checked_mul (&maxsize, max_width, max_height) || + ! g_size_checked_mul (&maxsize, maxsize, 4) || + ! (buf = g_try_new (guchar, maxsize))) { g_free (info); fclose (fp); @@ -865,6 +877,9 @@ ico_load_image (GFile *file, gimp_item_attach_parasite (GIMP_ITEM (layer), parasite); gimp_parasite_free (parasite); } + + if (! file_offset) + gimp_progress_update (i / (gfloat) icon_count); } if (file_offset) @@ -1242,7 +1257,8 @@ ico_load_thumbnail_image (GFile *file, image = gimp_image_new (info[match].width, info[match].height, GIMP_RGB); buf = g_new (guchar, info[match].width * info[match].height * 4); - ico_load_layer (fp, image, match, buf, info[match].width * info[match].height * 4, + ico_load_layer (fp, image, match, buf, + info[match].width * info[match].height * 4, file_offset, "Thumbnail", info + match); g_free (buf); -- 2.55.0 ++++++ gimp-CVE-2026-90949.patch ++++++ >From 0ff8049449b00bdd906faad7fcea091de8aa00a5 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Fri, 11 Sep 2026 11:03:22 +0000 Subject: [PATCH] plug-ins: Use buffer size for PSP selection loading It is possible that the buffer size for a selection and the reported selection size in a PSP file are not identical. This patch enforces using the buffer size for allocation so that we don't overflow the buffer when loading selections. --- plug-ins/common/file-psp.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/plug-ins/common/file-psp.c b/plug-ins/common/file-psp.c index 75807e2e8b..ccba3833a1 100644 --- a/plug-ins/common/file-psp.c +++ b/plug-ins/common/file-psp.c @@ -2588,7 +2588,11 @@ read_selection_block (FILE *f, return -1; } - pixels = g_try_malloc0 ((gsize) width * height); + selection = gimp_image_get_selection (image); + buffer = gimp_drawable_get_buffer (GIMP_DRAWABLE (selection)); + + pixels = g_try_malloc0 ((gsize) gegl_buffer_get_width (buffer) * + gegl_buffer_get_height (buffer)); if (pixels == NULL) { g_set_error (error, G_FILE_ERROR, G_FILE_ERROR_FAILED, @@ -2596,9 +2600,6 @@ read_selection_block (FILE *f, return -1; } - selection = gimp_image_get_selection (image); - buffer = gimp_drawable_get_buffer (GIMP_DRAWABLE (selection)); - /* Per the specification, this will always be a 1 byte grayscale channel */ if (ia->compression == PSP_COMP_NONE) { -- 2.55.0 ++++++ gimp-CVE-2026-92248-2.patch ++++++ >From 147b11937f2437ff1b5730d0be44bbf1fbacdae7 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Tue, 15 Sep 2026 17:17:46 +0000 Subject: [PATCH] plug-ins: Further PSD thumbnail cleanup from 6b1e6686 The security fixes introduced in 6b1e6686 also introduced new potential issues. We now add a check for if the rgb_buf is not NULL before trying to load it. We also close the file and libjpeg object if memory can't be allocated before returning. --- plug-ins/file-psd/psd-image-res-load.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/plug-ins/file-psd/psd-image-res-load.c b/plug-ins/file-psd/psd-image-res-load.c index 990f47d4b6..676fc6ac48 100644 --- a/plug-ins/file-psd/psd-image-res-load.c +++ b/plug-ins/file-psd/psd-image-res-load.c @@ -1105,6 +1105,9 @@ load_resource_1033 (const PSDimageres *res_a, ! (buf = g_try_new0 (guchar, alloc))) { psd_set_error (error); + jpeg_destroy_decompress (&cinfo); + fclose (f); + return -1; } @@ -1136,7 +1139,7 @@ load_resource_1033 (const PSDimageres *res_a, (JSAMPARRAY) &rowbuf[cinfo.output_scanline], 1); } - if (res_a->id == PSD_THUMB_RES) /* Order is BGR for resource 1033 */ + if (res_a->id == PSD_THUMB_RES && rgb_buf) /* Order is BGR for resource 1033 */ { guchar *dst = rgb_buf; guchar *src = buf; -- 2.55.0 ++++++ gimp-CVE-2026-92248.patch ++++++ >From 6b1e668699ebebc35152ad6c3db4b445cd78b7df Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Tue, 15 Sep 2026 11:05:37 +0000 Subject: [PATCH] plug-ins: Add bounds checks for PSD thumbnail The PSD thumbnail block calculated the memory it needed to allocate based on 32bit integer division. It was possible for this calculation to overflow with no checks. This patch replaces that math with a gsize variable and g_size_checked_mul () verification to ensure we allocate sufficient memory. Checks against GIMP_MAX_IMAGE_SIZE are also made to ensure the thumbnail isn't larger than the largest supported image size. --- plug-ins/file-psd/psd-image-res-load.c | 49 +++++++++++++++----------- 1 file changed, 29 insertions(+), 20 deletions(-) diff --git a/plug-ins/file-psd/psd-image-res-load.c b/plug-ins/file-psd/psd-image-res-load.c index 8d7171ca09..990f47d4b6 100644 --- a/plug-ins/file-psd/psd-image-res-load.c +++ b/plug-ins/file-psd/psd-image-res-load.c @@ -1018,20 +1018,22 @@ load_resource_1033 (const PSDimageres *res_a, { /* Load thumbnail image */ - struct jpeg_decompress_struct cinfo; - struct jpeg_error_mgr jerr; - - FILE *f; - ThumbnailInfo thumb_info; - GeglBuffer *buffer; - const Babl *format; - GimpLayer *layer; - guchar *buf; - guchar *rgb_buf; - guchar **rowbuf; - gint i; - - IFDBG(2) g_debug ("Process image resource block %d: Thumbnail Image", res_a->id); + struct jpeg_decompress_struct cinfo; + struct jpeg_error_mgr jerr; + + FILE *f; + ThumbnailInfo thumb_info; + GeglBuffer *buffer; + const Babl *format; + GimpLayer *layer; + guchar *buf; + guchar *rgb_buf; + guchar **rowbuf; + gsize alloc = 0; + gint i; + + IFDBG(2) g_debug ("Process image resource block %d: Thumbnail Image", + res_a->id); /* Read thumbnail resource header info */ if (psd_read (input, &thumb_info.format, 4, error) < 4 || @@ -1077,14 +1079,14 @@ load_resource_1033 (const PSDimageres *res_a, return -1; /* Now seek to the same position as we have in input. */ - fseek(f, g_seekable_tell (G_SEEKABLE (input)), SEEK_SET); + fseek (f, g_seekable_tell (G_SEEKABLE (input)), SEEK_SET); /* Step 1: Allocate and initialize JPEG decompression object */ cinfo.err = jpeg_std_error (&jerr); jpeg_create_decompress (&cinfo); /* Step 2: specify data source (eg, a file) */ - jpeg_stdio_src(&cinfo, f); + jpeg_stdio_src (&cinfo, f); /* Step 3: read file parameters with jpeg_read_header() */ jpeg_read_header (&cinfo, TRUE); @@ -1096,11 +1098,18 @@ load_resource_1033 (const PSDimageres *res_a, jpeg_start_decompress (&cinfo); /* temporary buffers */ - buf = g_new (guchar, cinfo.output_height * cinfo.output_width - * cinfo.output_components); + if (cinfo.output_width > GIMP_MAX_IMAGE_SIZE || + cinfo.output_height > GIMP_MAX_IMAGE_SIZE || + ! g_size_checked_mul (&alloc, cinfo.output_height, cinfo.output_width) || + ! g_size_checked_mul (&alloc, alloc, cinfo.output_components) || + ! (buf = g_try_new0 (guchar, alloc))) + { + psd_set_error (error); + return -1; + } + if (res_a->id == PSD_THUMB_RES) - rgb_buf = g_new (guchar, cinfo.output_height * cinfo.output_width - * cinfo.output_components); + rgb_buf = g_try_new0 (guchar, alloc); else rgb_buf = NULL; rowbuf = g_new (guchar *, cinfo.output_height); -- 2.55.0 ++++++ gimp-CVE-2026-96543.patch ++++++ >From 14a6ea47ec915a5e84ff580a1b2630ab30f1f814 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Tue, 22 Sep 2026 20:56:54 +0000 Subject: [PATCH] plug-ins: Check destination offset in PVR import Resolves #16789 While we checked if we had outrun the source buffer when importing twiddled PVR images, we did not check if we had exceeded the size of the destination buffer with the offset. This patch adds that check. --- plug-ins/common/file-pvr.c | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c index bab2c5dbd2..e9f74b8e13 100644 --- a/plug-ins/common/file-pvr.c +++ b/plug-ins/common/file-pvr.c @@ -759,14 +759,16 @@ pvr_decode_twiddle (GimpLayer *layer, { gint twiddle[MAX_TWIDDLE_SIZE]; GeglBuffer *buffer; - guint end = 0; - gint distance = 0; - gint stride = 0; - gint offset = 0; + guint end = 0; + gint distance = 0; + gint stride = 0; + gint offset = 0; + gsize pixel_size = 0; guchar *pixels; - pixels = g_try_malloc0 (width * height * n_components); - if (pixels == NULL) + if (! g_size_checked_mul (&pixel_size, width, height) || + ! g_size_checked_mul (&pixel_size, pixel_size, n_components) || + ! (pixels = g_try_malloc0 (pixel_size))) return FALSE; /* Initialize twiddle look up table */ @@ -804,8 +806,9 @@ pvr_decode_twiddle (GimpLayer *layer, offset2 += mipmap_offset; - if (offset2 + 1 >= data_size) - return FALSE; + if ((offset2 + 1) >= data_size || + (offset + n_components) > pixel_size) + break; p = data[offset2] | (data[offset2 + 1] << 8); if (! pvr_decode_color (pixel_mode, p, pixels, offset)) -- 2.55.0 ++++++ gimp-CVE-2026-96544-2.patch ++++++ >From 99e2547e54f8f83c6041586c2717a4be56e5ae5f Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Wed, 23 Sep 2026 12:25:40 +0000 Subject: [PATCH] plug-ins: Fix double allocation in PVR The security checks in 5f9b1ee7 did not remove the original allocation code, so memory was allocated twice. This patch removes the second allocation, and also adds bounds checking for the source data allocation. --- plug-ins/common/file-pvr.c | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c index e9f74b8e13..e81fccdc95 100644 --- a/plug-ins/common/file-pvr.c +++ b/plug-ins/common/file-pvr.c @@ -703,15 +703,11 @@ pvr_decode_rect (GimpLayer *layer, (pixels = g_try_malloc0 (pixel_size)) == NULL) return FALSE; - count = width * height * 2; - data = g_try_malloc0 (count); - if (data == NULL) - return FALSE; - - pixels = g_try_malloc0 (pixel_size); - if (pixels == NULL) + if (! g_size_checked_mul (&count, (guint32) width, height) || + ! g_size_checked_mul (&count, count, 2) || + (data = g_try_malloc0 (count)) == NULL) { - g_free (data); + g_free (pixels); return FALSE; } -- 2.55.0 ++++++ gimp-CVE-2026-96544.patch ++++++ >From 5f9b1ee7b09e738d95bb5ae36703ee2d772a3e27 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Sat, 19 Sep 2026 20:32:02 +0000 Subject: [PATCH] plug-ins: Add bounds checks for rectangle PVRs Resolves #16790 Adds the same allocation bounds to pvr_decode_rect () that we applied to other PVR import functions in 9c56e991. --- plug-ins/common/file-pvr.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c index 521aa66354..bab2c5dbd2 100644 --- a/plug-ins/common/file-pvr.c +++ b/plug-ins/common/file-pvr.c @@ -696,13 +696,19 @@ pvr_decode_rect (GimpLayer *layer, gsize count; guchar *pixels; guchar *data; + gsize pixel_size; + + if (! g_size_checked_mul (&pixel_size, (guint32) width, height) || + ! g_size_checked_mul (&pixel_size, pixel_size, n_components) || + (pixels = g_try_malloc0 (pixel_size)) == NULL) + return FALSE; count = width * height * 2; - data = g_try_malloc (count); + data = g_try_malloc0 (count); if (data == NULL) return FALSE; - pixels = g_try_malloc (width * height * n_components); + pixels = g_try_malloc0 (pixel_size); if (pixels == NULL) { g_free (data); -- 2.55.0 ++++++ gimp-CVE-2026-96545.patch ++++++ >From 2cd534781eee18e7cc7d98fa6b20458219cff036 Mon Sep 17 00:00:00 2001 From: Alx Sa <[email protected]> Date: Sat, 19 Sep 2026 20:15:35 +0000 Subject: [PATCH] plug-ins: Guard loading 4BPP TIM images Resolves #16791 If a 4BPP TIM image exceeds 255 color indices, (our current palette limit in GIMP), we promote it to RGB. However, we did not expand the space needed to load these images in our plug-in. This patch adds a check for 4BPP TIM images promoted to full color, and used the same technique for loading them as we do for the 8BPP route. --- plug-ins/common/file-tim.c | 57 +++++++++++++++++++++++++++++--------- 1 file changed, 44 insertions(+), 13 deletions(-) diff --git a/plug-ins/common/file-tim.c b/plug-ins/common/file-tim.c index 3d4b7ed5db..c1fc52f13a 100644 --- a/plug-ins/common/file-tim.c +++ b/plug-ins/common/file-tim.c @@ -564,11 +564,14 @@ load_image (GFile *file, if (tim_header.type[0] == PSX_4BPP) { guchar *pixels; + guchar *rgb_pixels; guchar *row; - pixels = g_try_malloc0 (width); - row = g_try_malloc0 (width * 2); - if (! pixels || ! row) + pixels = g_try_malloc0 (width); + rgb_pixels = g_try_malloc0 (width * 8); + row = g_try_malloc0 (width * 2); + + if (! pixels || ! rgb_pixels || ! row) { g_set_error (error, G_FILE_ERROR, 0, _("Memory could not be allocated.")); @@ -581,15 +584,42 @@ load_image (GFile *file, { if (fread (pixels, width, 1, fp) > 0) { - for (gint j = 0; j < width; j++) + if (! promote_to_rgb) { - row[j * 2] = pixels[j] & 0x0F; - row[j * 2 + 1] = pixels[j] >> 4; + for (gint j = 0; j < width; j++) + { + row[j * 2] = pixels[j] & 0x0F; + row[j * 2 + 1] = pixels[j] >> 4; + } + + gegl_buffer_set (buffer, + GEGL_RECTANGLE (0, (i * 2), width, 2), + 0, NULL, row, GEGL_AUTO_ROWSTRIDE); } + else + { + gint index = 0; - gegl_buffer_set (buffer, - GEGL_RECTANGLE (0, (i * 2), width, 2), 0, - NULL, row, GEGL_AUTO_ROWSTRIDE); + for (gint j = 0; j < width; j += 2) + { + index = pixels[j] & 0x0F; + + for (gint k = 0; k < 4; k++) + rgb_pixels[(j * 4) + k] = + color_map[index * 4 + k]; + + index = pixels[j] >> 4; + + for (gint k = 0; k < 4; k++) + rgb_pixels[((j + 1) * 4) + k] = + color_map[index * 4 + k]; + } + + gegl_buffer_set (buffer, + GEGL_RECTANGLE (0, i, width, 1), 0, + NULL, rgb_pixels, + GEGL_AUTO_ROWSTRIDE); + } } else { @@ -599,6 +629,7 @@ load_image (GFile *file, } g_free (pixels); g_free (row); + g_free (rgb_pixels); } else if (tim_header.type[0] == PSX_8BPP) { @@ -630,11 +661,11 @@ load_image (GFile *file, { gint index = 0; - for (gint i = 0; i < width; i++) + for (gint j = 0; j < width; j++) { - index = pixels[i]; - for (gint j = 0; j < 4; j++) - rgb_pixels[(i * 4) + j] = color_map[index * 4 + j]; + index = pixels[j]; + for (gint k = 0; k < 4; k++) + rgb_pixels[(j * 4) + k] = color_map[index * 4 + k]; } gegl_buffer_set (buffer, -- 2.55.0 ++++++ gimp-initialize-sgi-tables.patch ++++++ >From 6bf279b6c1f868f2e6df9567c664731037d9646c Mon Sep 17 00:00:00 2001 From: Mike Gorse <[email protected]> Date: Thu, 10 Sep 2026 13:53:03 -0500 Subject: [PATCH] plugins: Ensure that SGI tables are initialized Call g_try_malloc0, rather than g_try_malloc, when allocating tables. This avoids potentially using uninitialized memory and matches the previous behavior of calling calloc. Related to #16494 --- plug-ins/file-sgi/sgi-lib.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/plug-ins/file-sgi/sgi-lib.c b/plug-ins/file-sgi/sgi-lib.c index 534ceaaa25..2c6e9f8f4e 100644 --- a/plug-ins/file-sgi/sgi-lib.c +++ b/plug-ins/file-sgi/sgi-lib.c @@ -352,8 +352,8 @@ sgiOpenFile(FILE *file, /* I - File to open */ free(sgip); return (NULL); } - sgip->table[0] = g_try_malloc ((gsize) sgip->ysize * sgip->zsize * - sizeof (goffset)); + sgip->table[0] = g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize * + sizeof (goffset)); if (sgip->table[0] == NULL) { free(sgip->table); @@ -454,8 +454,8 @@ sgiOpenFile(FILE *file, /* I - File to open */ return (NULL); } sgip->table[0] = - g_try_malloc ((gsize) sgip->ysize * sgip->zsize * - sizeof (goffset)); + g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize * + sizeof (goffset)); if (sgip->table[0] == NULL) { free(sgip->table); @@ -467,8 +467,8 @@ sgiOpenFile(FILE *file, /* I - File to open */ sgip->table[i] = sgip->table[0] + i * sgip->ysize; sgip->length = calloc(sgip->zsize, sizeof(goffset *)); sgip->length[0] = - g_try_malloc ((gsize) sgip->ysize * sgip->zsize * - sizeof (goffset)); + g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize * + sizeof (goffset)); for (i = 1; i < sgip->zsize; i ++) sgip->length[i] = sgip->length[0] + i * sgip->ysize; break; -- 2.55.0
