Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gimp for openSUSE:Factory checked in 
at 2026-09-28 10:36:53
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gimp (Old)
 and      /work/SRC/openSUSE:Factory/.gimp.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gimp"

Mon Sep 28 10:36:53 2026 rev:174 rq:1380314 version:3.2.6

Changes:
--------
--- /work/SRC/openSUSE:Factory/gimp/gimp.changes        2026-09-24 
22:55:24.168052316 +0200
+++ /work/SRC/openSUSE:Factory/.gimp.new.383539/gimp.changes    2026-09-28 
10:37:51.116338091 +0200
@@ -1,0 +2,36 @@
+Thu Sep 24 18:02:06 UTC 2026 - Michael Gorse <[email protected]>
+
+- CVE-2026-96543: out-of-bounds heap write when loading non-square
+  PVR images (bsc#1282539)
+  * gimp-CVE-2026-96543.patch
+- CVE-2026-96544: integer overflow in the PVR image loader leads to
+  an out-of-bounds heap read (bsc#1282541)
+  * gimp-CVE-2026-96544.patch
+  * gimp-CVE-2026-96544-2.patch
+- CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image
+  loader (bsc#1282602)
+  * gimp-CVE-2026-96545.patch
+
+-------------------------------------------------------------------
+Wed Sep 23 14:49:04 UTC 2026 - Michael Gorse <[email protected]>
+
+- Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are
+  initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838
+  glgo#GNOME/gimp!2997).
+- CVE-2026-90948: When processing an ICO file containing an
+  embedded PNG image, an integer overflow can occur during the
+  calculation of the required buffer size (bsc#1280512)
+  * gimp-CVE-2026-90948.patch
+- CVE-2026-90949: When processing a compressed selection channel in
+  gimp's PSP file loader, a heap-based buffer overflow can occur
+  due to a mismatch between the allocated buffer size and the
+  amount of data decompressed (bsc#1280513)
+  * gimp-CVE-2026-90949.patch
+- CVE-2026-92248: When generating a thumbnail preview for a
+  specially crafted PSD (Photoshop Document) image file, an integer
+  overflow occurs during the multiplication of values from an
+  embedded JPEG header (bsc#1280739)
+  * gimp-CVE-2026-92248.patch
+  * gimp-CVE-2026-92248-2.patch
+
+-------------------------------------------------------------------

New:
----
  gimp-CVE-2026-90948.patch
  gimp-CVE-2026-90949.patch
  gimp-CVE-2026-92248-2.patch
  gimp-CVE-2026-92248.patch
  gimp-CVE-2026-96543.patch
  gimp-CVE-2026-96544-2.patch
  gimp-CVE-2026-96544.patch
  gimp-CVE-2026-96545.patch
  gimp-initialize-sgi-tables.patch

----------(New B)----------
  New:  calculation of the required buffer size (bsc#1280512)
  * gimp-CVE-2026-90948.patch
- CVE-2026-90949: When processing a compressed selection channel in
  New:  amount of data decompressed (bsc#1280513)
  * gimp-CVE-2026-90949.patch
- CVE-2026-92248: When generating a thumbnail preview for a
  New:  * gimp-CVE-2026-92248.patch
  * gimp-CVE-2026-92248-2.patch
  New:  embedded JPEG header (bsc#1280739)
  * gimp-CVE-2026-92248.patch
  * gimp-CVE-2026-92248-2.patch
  New:  PVR images (bsc#1282539)
  * gimp-CVE-2026-96543.patch
- CVE-2026-96544: integer overflow in the PVR image loader leads to
  New:  * gimp-CVE-2026-96544.patch
  * gimp-CVE-2026-96544-2.patch
- CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image
  New:  an out-of-bounds heap read (bsc#1282541)
  * gimp-CVE-2026-96544.patch
  * gimp-CVE-2026-96544-2.patch
  New:  loader (bsc#1282602)
  * gimp-CVE-2026-96545.patch
  New:
- Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are
  initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ gimp.spec ++++++
--- /var/tmp/diff_new_pack.j2evqn/_old  2026-09-28 10:37:52.238385011 +0200
+++ /var/tmp/diff_new_pack.j2evqn/_new  2026-09-28 10:37:52.239385053 +0200
@@ -104,6 +104,24 @@
 Patch3:         gimp-2.99.19-no-phone-home-default.patch
 # PATCH-FIX-UPSTREAM gimp-fix-invalid-XWD-guards.patch glgo#GNOME/gimp!3007, 
bsc#1279839 [email protected] -- Fix invalid guards for XWD parameters
 Patch4:         gimp-fix-invalid-XWD-guards.patch
+# PATCH-FIX-UPSTREAM gimp-initialize-sgi-tables.patch bsc#1279838 
[email protected] -- ensure that SGI tables are initialized.
+Patch5:         gimp-initialize-sgi-tables.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-90948.patch bsc#1280512 [email protected] -- 
Stop overflow when reading PNGs in ICO.
+Patch6:         gimp-CVE-2026-90948.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-90949.patch bsc#1280513 [email protected] -- 
Use buffer size for PSP selection loading.
+Patch7:         gimp-CVE-2026-90949.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-92248.patch bsc#1280739 [email protected] -- 
Add bounds checks for PSD thumbnail.
+Patch8:         gimp-CVE-2026-92248.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-92248-2.patch bsc#1280739 [email protected] 
-- Further PSD thumbnail cleanup.
+Patch9:         gimp-CVE-2026-92248-2.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-96543.patch bsc#1282539 [email protected] -- 
Check destination offset in PVR import.
+Patch10:        gimp-CVE-2026-96543.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-96544.patch bsc#1282541 [email protected] -- 
Add bounds checks for rectangle PVRs.
+Patch11:        gimp-CVE-2026-96544.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-96544-2.patch bsc#1282541 [email protected] 
-- Fix double allocation in PVR.
+Patch12:        gimp-CVE-2026-96544-2.patch
+# PATCH-FIX-UPSTREAM gimp-CVE-2026-96545.patch bsc#1282602 [email protected] -- 
Guard loading 4BPP TIM images.
+Patch13:        gimp-CVE-2026-96545.patch
 %if %{with debug_in_build_gimp}
 BuildRequires:  gdb
 %endif

++++++ gimp-CVE-2026-90948.patch ++++++
>From 123d6360b8d7e2a00a9d913889ee9cdca88e2380 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Wed, 9 Sep 2026 13:42:27 +0000
Subject: [PATCH] plug-ins: Stop overflow when reading PNGs in ICO

This patch converts gints used in getting the total area of
a PNG loaded from an ICO file to gsize. It also uses
g_size_checked_mul () to do the overflow checks instead of straight
32 bit multiplication, for better security.
---
 plug-ins/file-ico/ico-load.c | 62 +++++++++++++++++++++++-------------
 1 file changed, 39 insertions(+), 23 deletions(-)

diff --git a/plug-ins/file-ico/ico-load.c b/plug-ins/file-ico/ico-load.c
index da39a3bfa6..ce531b93e6 100644
--- a/plug-ins/file-ico/ico-load.c
+++ b/plug-ins/file-ico/ico-load.c
@@ -274,7 +274,7 @@ static gboolean
 ico_read_png (FILE    *fp,
               guint32  header,
               guchar  *buf,
-              gint     maxsize,
+              gsize    maxsize,
               gint    *width,
               gint    *height,
               gint    *bpp)
@@ -283,6 +283,7 @@ ico_read_png (FILE    *fp,
   png_infop     info;
   png_uint_32   w;
   png_uint_32   h;
+  gsize         total_size;
   gint32        bit_depth;
   gint32        color_type;
   guint32     **rows;
@@ -310,15 +311,14 @@ ico_read_png (FILE    *fp,
   png_get_IHDR (png_ptr, info, &w, &h, &bit_depth, &color_type,
                 NULL, NULL, NULL);
   /* Check for overflow */
-  if ((w * h * 4) < w       ||
-      (w * h * 4) < h       ||
-      (w * h * 4) < (w * h) ||
-      (w * h * 4) > maxsize)
+  if (! g_size_checked_mul (&total_size, w, h)          ||
+      ! g_size_checked_mul (&total_size, total_size, 4) ||
+      total_size > maxsize)
     {
       png_destroy_read_struct (&png_ptr, &info, NULL);
       return FALSE;
     }
-  D(("ico_read_png: %ix%i, %i bits, %i type\n", (gint)w, (gint)h,
+  D(("ico_read_png: %ix%i, %i bits, %i type\n", (gint) w, (gint) h,
      bit_depth, color_type));
   switch (color_type)
     {
@@ -353,13 +353,13 @@ ico_read_png (FILE    *fp,
       break;
     }
 
-  *width = w;
+  *width  = w;
   *height = h;
-  *bpp = 32; /* always expanded to 32bpp RGBA */
-  rows = g_new (guint32*, h);
-  rows[0] = (guint32*) buf;
+  *bpp    = 32; /* always expanded to 32bpp RGBA */
+  rows    = g_new (guint32 *, h);
+  rows[0] = (guint32 *) buf;
   for (i = 1; i < h; i++)
-    rows[i] = rows[i-1] + w;
+    rows[i] = rows[i - 1] + w;
   png_read_image (png_ptr, (png_bytepp) rows);
   png_destroy_read_struct (&png_ptr, &info, NULL);
   g_free (rows);
@@ -432,7 +432,7 @@ static gboolean
 ico_read_icon (FILE    *fp,
                guint32  header_size,
                guchar  *buf,
-               gint     maxsize,
+               gsize    maxsize,
                gint    *width,
                gint    *height,
                gint    *bpp)
@@ -683,7 +683,7 @@ ico_load_layer (FILE        *fp,
                 GimpImage   *image,
                 gint32       icon_num,
                 guchar      *buf,
-                gint         maxsize,
+                gsize        maxsize,
                 gint32       file_offset,
                 gchar       *layer_prefix,
                 IcoLoadInfo *info)
@@ -699,8 +699,8 @@ ico_load_layer (FILE        *fp,
 
   if (first_bytes == ICO_PNG_MAGIC)
     {
-      if (!ico_read_png (fp, first_bytes, buf, maxsize, &width, &height,
-                         &info->bpp))
+      if (! ico_read_png (fp, first_bytes, buf, maxsize, &width, &height,
+                          &info->bpp))
         return NULL;
     }
   else if (first_bytes == 40)
@@ -744,12 +744,13 @@ ico_load_image (GFile        *file,
   FILE          *fp;
   IcoFileHeader  header;
   IcoLoadInfo   *info;
-  gint           max_width, max_height;
+  gsize          max_width;
+  gsize          max_height;
   gint           i;
   GimpImage     *image;
   guchar        *buf;
   guint          icon_count;
-  gint           maxsize;
+  gsize          maxsize;
   gchar         *str;
 
   if (! file_offset)
@@ -769,7 +770,7 @@ ico_load_image (GFile        *file,
   if (file_offset)
     fseek (fp, *file_offset, SEEK_SET);
 
-  header = ico_read_init (fp);
+  header     = ico_read_init (fp);
   icon_count = header.icon_count;
   if (!icon_count)
     {
@@ -794,7 +795,9 @@ ico_load_image (GFile        *file,
       if (info[i].height > max_height)
         max_height = info[i].height;
     }
-  if (max_width <= 0 || max_height <= 0)
+  if (max_width <= 0 || max_height <= 0 ||
+      max_width > GIMP_MAX_IMAGE_SIZE   ||
+      max_height > GIMP_MAX_IMAGE_SIZE)
     {
       g_free (info);
       fclose (fp);
@@ -804,9 +807,18 @@ ico_load_image (GFile        *file,
 
   image = gimp_image_new (max_width, max_height, GIMP_RGB);
 
-  maxsize = max_width * max_height * 4;
-  buf     = g_try_new (guchar, maxsize);
-  if (! buf)
+  if (max_width <= 0 || max_height <= 0 ||
+      max_width > GIMP_MAX_IMAGE_SIZE   ||
+      max_height > GIMP_MAX_IMAGE_SIZE)
+    {
+      g_free (info);
+      fclose (fp);
+      return NULL;
+    }
+
+  if (! g_size_checked_mul (&maxsize, max_width, max_height) ||
+      ! g_size_checked_mul (&maxsize, maxsize, 4)            ||
+      ! (buf = g_try_new (guchar, maxsize)))
     {
       g_free (info);
       fclose (fp);
@@ -865,6 +877,9 @@ ico_load_image (GFile        *file,
           gimp_item_attach_parasite (GIMP_ITEM (layer), parasite);
           gimp_parasite_free (parasite);
         }
+
+      if (! file_offset)
+        gimp_progress_update (i / (gfloat) icon_count);
     }
 
   if (file_offset)
@@ -1242,7 +1257,8 @@ ico_load_thumbnail_image (GFile   *file,
 
   image = gimp_image_new (info[match].width, info[match].height, GIMP_RGB);
   buf   = g_new (guchar, info[match].width * info[match].height * 4);
-  ico_load_layer (fp, image, match, buf, info[match].width * 
info[match].height * 4,
+  ico_load_layer (fp, image, match, buf,
+                  info[match].width * info[match].height * 4,
                   file_offset, "Thumbnail", info + match);
   g_free (buf);
 
-- 
2.55.0


++++++ gimp-CVE-2026-90949.patch ++++++
>From 0ff8049449b00bdd906faad7fcea091de8aa00a5 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Fri, 11 Sep 2026 11:03:22 +0000
Subject: [PATCH] plug-ins: Use buffer size for PSP selection loading

It is possible that the buffer size for a selection and the
reported selection size in a PSP file are not identical. This
patch enforces using the buffer size for allocation so that we
don't overflow the buffer when loading selections.
---
 plug-ins/common/file-psp.c | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/plug-ins/common/file-psp.c b/plug-ins/common/file-psp.c
index 75807e2e8b..ccba3833a1 100644
--- a/plug-ins/common/file-psp.c
+++ b/plug-ins/common/file-psp.c
@@ -2588,7 +2588,11 @@ read_selection_block (FILE      *f,
       return -1;
     }
 
-  pixels = g_try_malloc0 ((gsize) width * height);
+  selection = gimp_image_get_selection (image);
+  buffer    = gimp_drawable_get_buffer (GIMP_DRAWABLE (selection));
+
+  pixels = g_try_malloc0 ((gsize) gegl_buffer_get_width (buffer) *
+                          gegl_buffer_get_height (buffer));
   if (pixels == NULL)
     {
       g_set_error (error, G_FILE_ERROR, G_FILE_ERROR_FAILED,
@@ -2596,9 +2600,6 @@ read_selection_block (FILE      *f,
       return -1;
     }
 
-  selection = gimp_image_get_selection (image);
-  buffer    = gimp_drawable_get_buffer (GIMP_DRAWABLE (selection));
-
   /* Per the specification, this will always be a 1 byte grayscale channel */
   if (ia->compression == PSP_COMP_NONE)
     {
-- 
2.55.0


++++++ gimp-CVE-2026-92248-2.patch ++++++
>From 147b11937f2437ff1b5730d0be44bbf1fbacdae7 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Tue, 15 Sep 2026 17:17:46 +0000
Subject: [PATCH] plug-ins: Further PSD thumbnail cleanup from 6b1e6686

The security fixes introduced in 6b1e6686
also introduced new potential issues.
We now add a check for if the rgb_buf
is not NULL before trying to load it.
We also close the file and libjpeg object
if memory can't be allocated before
returning.
---
 plug-ins/file-psd/psd-image-res-load.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/plug-ins/file-psd/psd-image-res-load.c 
b/plug-ins/file-psd/psd-image-res-load.c
index 990f47d4b6..676fc6ac48 100644
--- a/plug-ins/file-psd/psd-image-res-load.c
+++ b/plug-ins/file-psd/psd-image-res-load.c
@@ -1105,6 +1105,9 @@ load_resource_1033 (const PSDimageres  *res_a,
       ! (buf = g_try_new0 (guchar, alloc)))
     {
       psd_set_error (error);
+      jpeg_destroy_decompress (&cinfo);
+      fclose (f);
+
       return -1;
     }
 
@@ -1136,7 +1139,7 @@ load_resource_1033 (const PSDimageres  *res_a,
                            (JSAMPARRAY) &rowbuf[cinfo.output_scanline], 1);
     }
 
-  if (res_a->id == PSD_THUMB_RES)   /* Order is BGR for resource 1033 */
+  if (res_a->id == PSD_THUMB_RES && rgb_buf) /* Order is BGR for resource 1033 
*/
     {
       guchar *dst = rgb_buf;
       guchar *src = buf;
-- 
2.55.0


++++++ gimp-CVE-2026-92248.patch ++++++
>From 6b1e668699ebebc35152ad6c3db4b445cd78b7df Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Tue, 15 Sep 2026 11:05:37 +0000
Subject: [PATCH] plug-ins: Add bounds checks for PSD thumbnail

The PSD thumbnail block calculated the memory it needed to
allocate based on 32bit integer division. It was possible for
this calculation to overflow with no checks.
This patch replaces that math with a gsize variable and
g_size_checked_mul () verification to ensure we allocate
sufficient memory. Checks against GIMP_MAX_IMAGE_SIZE are
also made to ensure the thumbnail isn't larger than the largest
supported image size.
---
 plug-ins/file-psd/psd-image-res-load.c | 49 +++++++++++++++-----------
 1 file changed, 29 insertions(+), 20 deletions(-)

diff --git a/plug-ins/file-psd/psd-image-res-load.c 
b/plug-ins/file-psd/psd-image-res-load.c
index 8d7171ca09..990f47d4b6 100644
--- a/plug-ins/file-psd/psd-image-res-load.c
+++ b/plug-ins/file-psd/psd-image-res-load.c
@@ -1018,20 +1018,22 @@ load_resource_1033 (const PSDimageres  *res_a,
 {
   /* Load thumbnail image */
 
-  struct jpeg_decompress_struct cinfo;
-  struct jpeg_error_mgr         jerr;
-
-  FILE                 *f;
-  ThumbnailInfo         thumb_info;
-  GeglBuffer           *buffer;
-  const Babl           *format;
-  GimpLayer            *layer;
-  guchar               *buf;
-  guchar               *rgb_buf;
-  guchar              **rowbuf;
-  gint                  i;
-
-  IFDBG(2) g_debug ("Process image resource block %d: Thumbnail Image", 
res_a->id);
+  struct jpeg_decompress_struct  cinfo;
+  struct jpeg_error_mgr          jerr;
+
+  FILE                          *f;
+  ThumbnailInfo                  thumb_info;
+  GeglBuffer                    *buffer;
+  const Babl                    *format;
+  GimpLayer                     *layer;
+  guchar                        *buf;
+  guchar                        *rgb_buf;
+  guchar                       **rowbuf;
+  gsize                          alloc = 0;
+  gint                           i;
+
+  IFDBG(2) g_debug ("Process image resource block %d: Thumbnail Image",
+                    res_a->id);
 
   /* Read thumbnail resource header info */
   if (psd_read (input, &thumb_info.format,         4, error) < 4 ||
@@ -1077,14 +1079,14 @@ load_resource_1033 (const PSDimageres  *res_a,
     return -1;
 
   /* Now seek to the same position as we have in input. */
-  fseek(f, g_seekable_tell (G_SEEKABLE (input)), SEEK_SET);
+  fseek (f, g_seekable_tell (G_SEEKABLE (input)), SEEK_SET);
 
   /* Step 1: Allocate and initialize JPEG decompression object */
   cinfo.err = jpeg_std_error (&jerr);
   jpeg_create_decompress (&cinfo);
 
   /* Step 2: specify data source (eg, a file) */
-  jpeg_stdio_src(&cinfo, f);
+  jpeg_stdio_src (&cinfo, f);
 
   /* Step 3: read file parameters with jpeg_read_header() */
   jpeg_read_header (&cinfo, TRUE);
@@ -1096,11 +1098,18 @@ load_resource_1033 (const PSDimageres  *res_a,
   jpeg_start_decompress (&cinfo);
 
   /* temporary buffers */
-  buf = g_new (guchar, cinfo.output_height * cinfo.output_width
-               * cinfo.output_components);
+  if (cinfo.output_width > GIMP_MAX_IMAGE_SIZE                               ||
+      cinfo.output_height > GIMP_MAX_IMAGE_SIZE                              ||
+      ! g_size_checked_mul (&alloc, cinfo.output_height, cinfo.output_width) ||
+      ! g_size_checked_mul (&alloc, alloc, cinfo.output_components)          ||
+      ! (buf = g_try_new0 (guchar, alloc)))
+    {
+      psd_set_error (error);
+      return -1;
+    }
+
   if (res_a->id == PSD_THUMB_RES)
-    rgb_buf = g_new (guchar, cinfo.output_height * cinfo.output_width
-                     * cinfo.output_components);
+    rgb_buf = g_try_new0 (guchar, alloc);
   else
     rgb_buf = NULL;
   rowbuf = g_new (guchar *, cinfo.output_height);
-- 
2.55.0


++++++ gimp-CVE-2026-96543.patch ++++++
>From 14a6ea47ec915a5e84ff580a1b2630ab30f1f814 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Tue, 22 Sep 2026 20:56:54 +0000
Subject: [PATCH] plug-ins: Check destination offset in PVR import

Resolves #16789
While we checked if we had outrun the source buffer
when importing twiddled PVR images, we did not check
if we had exceeded the size of the destination buffer with
the offset. This patch adds that check.
---
 plug-ins/common/file-pvr.c | 19 +++++++++++--------
 1 file changed, 11 insertions(+), 8 deletions(-)

diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c
index bab2c5dbd2..e9f74b8e13 100644
--- a/plug-ins/common/file-pvr.c
+++ b/plug-ins/common/file-pvr.c
@@ -759,14 +759,16 @@ pvr_decode_twiddle (GimpLayer  *layer,
 {
   gint        twiddle[MAX_TWIDDLE_SIZE];
   GeglBuffer *buffer;
-  guint       end      = 0;
-  gint        distance = 0;
-  gint        stride   = 0;
-  gint        offset   = 0;
+  guint       end        = 0;
+  gint        distance   = 0;
+  gint        stride     = 0;
+  gint        offset     = 0;
+  gsize       pixel_size = 0;
   guchar     *pixels;
 
-  pixels = g_try_malloc0 (width * height * n_components);
-  if (pixels == NULL)
+  if (! g_size_checked_mul (&pixel_size, width, height)            ||
+      ! g_size_checked_mul (&pixel_size, pixel_size, n_components) ||
+      ! (pixels = g_try_malloc0 (pixel_size)))
     return FALSE;
 
   /* Initialize twiddle look up table */
@@ -804,8 +806,9 @@ pvr_decode_twiddle (GimpLayer  *layer,
 
               offset2 += mipmap_offset;
 
-              if (offset2 + 1 >= data_size)
-                return FALSE;
+              if ((offset2 + 1) >= data_size ||
+                  (offset + n_components) > pixel_size)
+                break;
 
               p = data[offset2] | (data[offset2 + 1] << 8);
               if (! pvr_decode_color (pixel_mode, p, pixels, offset))
-- 
2.55.0


++++++ gimp-CVE-2026-96544-2.patch ++++++
>From 99e2547e54f8f83c6041586c2717a4be56e5ae5f Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Wed, 23 Sep 2026 12:25:40 +0000
Subject: [PATCH] plug-ins: Fix double allocation in PVR

The security checks in 5f9b1ee7 did not remove
the original allocation code, so memory was allocated
twice. This patch removes the second allocation, and also
adds bounds checking for the source data allocation.
---
 plug-ins/common/file-pvr.c | 12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c
index e9f74b8e13..e81fccdc95 100644
--- a/plug-ins/common/file-pvr.c
+++ b/plug-ins/common/file-pvr.c
@@ -703,15 +703,11 @@ pvr_decode_rect (GimpLayer  *layer,
       (pixels = g_try_malloc0 (pixel_size)) == NULL)
     return FALSE;
 
-  count = width * height * 2;
-  data  = g_try_malloc0 (count);
-  if (data == NULL)
-    return FALSE;
-
-  pixels = g_try_malloc0 (pixel_size);
-  if (pixels == NULL)
+  if (! g_size_checked_mul (&count, (guint32) width, height)  ||
+      ! g_size_checked_mul (&count, count, 2) ||
+      (data = g_try_malloc0 (count)) == NULL)
     {
-      g_free (data);
+      g_free (pixels);
       return FALSE;
     }
 
-- 
2.55.0


++++++ gimp-CVE-2026-96544.patch ++++++
>From 5f9b1ee7b09e738d95bb5ae36703ee2d772a3e27 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Sat, 19 Sep 2026 20:32:02 +0000
Subject: [PATCH] plug-ins: Add bounds checks for rectangle PVRs

Resolves #16790
Adds the same allocation bounds to pvr_decode_rect ()
that we applied to other PVR import functions in
9c56e991.
---
 plug-ins/common/file-pvr.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/plug-ins/common/file-pvr.c b/plug-ins/common/file-pvr.c
index 521aa66354..bab2c5dbd2 100644
--- a/plug-ins/common/file-pvr.c
+++ b/plug-ins/common/file-pvr.c
@@ -696,13 +696,19 @@ pvr_decode_rect (GimpLayer  *layer,
   gsize       count;
   guchar     *pixels;
   guchar     *data;
+  gsize       pixel_size;
+
+  if (! g_size_checked_mul (&pixel_size, (guint32) width, height)  ||
+      ! g_size_checked_mul (&pixel_size, pixel_size, n_components) ||
+      (pixels = g_try_malloc0 (pixel_size)) == NULL)
+    return FALSE;
 
   count = width * height * 2;
-  data  = g_try_malloc (count);
+  data  = g_try_malloc0 (count);
   if (data == NULL)
     return FALSE;
 
-  pixels = g_try_malloc (width * height * n_components);
+  pixels = g_try_malloc0 (pixel_size);
   if (pixels == NULL)
     {
       g_free (data);
-- 
2.55.0


++++++ gimp-CVE-2026-96545.patch ++++++
>From 2cd534781eee18e7cc7d98fa6b20458219cff036 Mon Sep 17 00:00:00 2001
From: Alx Sa <[email protected]>
Date: Sat, 19 Sep 2026 20:15:35 +0000
Subject: [PATCH] plug-ins: Guard loading 4BPP TIM images

Resolves #16791
If a 4BPP TIM image exceeds 255 color indices,
(our current palette limit in GIMP), we promote it
to RGB. However, we did not expand the space needed
to load these images in our plug-in.
This patch adds a check for 4BPP TIM images promoted
to full color, and used the same technique for loading them
as we do for the 8BPP route.
---
 plug-ins/common/file-tim.c | 57 +++++++++++++++++++++++++++++---------
 1 file changed, 44 insertions(+), 13 deletions(-)

diff --git a/plug-ins/common/file-tim.c b/plug-ins/common/file-tim.c
index 3d4b7ed5db..c1fc52f13a 100644
--- a/plug-ins/common/file-tim.c
+++ b/plug-ins/common/file-tim.c
@@ -564,11 +564,14 @@ load_image (GFile        *file,
         if (tim_header.type[0] == PSX_4BPP)
           {
             guchar *pixels;
+            guchar *rgb_pixels;
             guchar *row;
 
-            pixels = g_try_malloc0 (width);
-            row    = g_try_malloc0 (width * 2);
-            if (! pixels || ! row)
+            pixels     = g_try_malloc0 (width);
+            rgb_pixels = g_try_malloc0 (width * 8);
+            row        = g_try_malloc0 (width * 2);
+
+            if (! pixels || ! rgb_pixels || ! row)
               {
                 g_set_error (error, G_FILE_ERROR, 0,
                              _("Memory could not be allocated."));
@@ -581,15 +584,42 @@ load_image (GFile        *file,
               {
                 if (fread (pixels, width, 1, fp) > 0)
                   {
-                    for (gint j = 0; j < width; j++)
+                    if (! promote_to_rgb)
                       {
-                        row[j * 2]     = pixels[j] & 0x0F;
-                        row[j * 2 + 1] = pixels[j] >> 4;
+                        for (gint j = 0; j < width; j++)
+                          {
+                            row[j * 2]     = pixels[j] & 0x0F;
+                            row[j * 2 + 1] = pixels[j] >> 4;
+                          }
+
+                        gegl_buffer_set (buffer,
+                                         GEGL_RECTANGLE (0, (i * 2), width, 2),
+                                         0, NULL, row, GEGL_AUTO_ROWSTRIDE);
                       }
+                    else
+                      {
+                        gint index = 0;
 
-                    gegl_buffer_set (buffer,
-                                     GEGL_RECTANGLE (0, (i * 2), width, 2), 0,
-                                     NULL, row, GEGL_AUTO_ROWSTRIDE);
+                        for (gint j = 0; j < width; j += 2)
+                          {
+                            index = pixels[j] & 0x0F;
+
+                            for (gint k = 0; k < 4; k++)
+                              rgb_pixels[(j * 4) + k] =
+                                color_map[index * 4 + k];
+
+                            index = pixels[j] >> 4;
+
+                            for (gint k = 0; k < 4; k++)
+                              rgb_pixels[((j + 1) * 4) + k] =
+                                color_map[index * 4 + k];
+                          }
+
+                        gegl_buffer_set (buffer,
+                                         GEGL_RECTANGLE (0, i, width, 1), 0,
+                                         NULL, rgb_pixels,
+                                         GEGL_AUTO_ROWSTRIDE);
+                      }
                   }
                 else
                   {
@@ -599,6 +629,7 @@ load_image (GFile        *file,
               }
             g_free (pixels);
             g_free (row);
+            g_free (rgb_pixels);
           }
         else if (tim_header.type[0] == PSX_8BPP)
           {
@@ -630,11 +661,11 @@ load_image (GFile        *file,
                       {
                         gint index = 0;
 
-                        for (gint i = 0; i < width; i++)
+                        for (gint j = 0; j < width; j++)
                           {
-                            index = pixels[i];
-                            for (gint j = 0; j < 4; j++)
-                              rgb_pixels[(i * 4) + j] = color_map[index * 4 + 
j];
+                            index = pixels[j];
+                            for (gint k = 0; k < 4; k++)
+                              rgb_pixels[(j * 4) + k] = color_map[index * 4 + 
k];
                           }
 
                         gegl_buffer_set (buffer,
-- 
2.55.0


++++++ gimp-initialize-sgi-tables.patch ++++++
>From 6bf279b6c1f868f2e6df9567c664731037d9646c Mon Sep 17 00:00:00 2001
From: Mike Gorse <[email protected]>
Date: Thu, 10 Sep 2026 13:53:03 -0500
Subject: [PATCH] plugins: Ensure that SGI tables are initialized

Call g_try_malloc0, rather than g_try_malloc, when allocating tables.
This avoids potentially using uninitialized memory and matches the previous
behavior of calling calloc.

Related to #16494
---
 plug-ins/file-sgi/sgi-lib.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/plug-ins/file-sgi/sgi-lib.c b/plug-ins/file-sgi/sgi-lib.c
index 534ceaaa25..2c6e9f8f4e 100644
--- a/plug-ins/file-sgi/sgi-lib.c
+++ b/plug-ins/file-sgi/sgi-lib.c
@@ -352,8 +352,8 @@ sgiOpenFile(FILE *file, /* I - File to open */
                 free(sgip);
                 return (NULL);
               }
-            sgip->table[0] = g_try_malloc ((gsize) sgip->ysize * sgip->zsize *
-                                           sizeof (goffset));
+            sgip->table[0] = g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize *
+                                            sizeof (goffset));
             if (sgip->table[0] == NULL)
               {
                 free(sgip->table);
@@ -454,8 +454,8 @@ sgiOpenFile(FILE *file, /* I - File to open */
                   return (NULL);
                 }
               sgip->table[0] =
-                g_try_malloc ((gsize) sgip->ysize * sgip->zsize *
-                              sizeof (goffset));
+                g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize *
+                               sizeof (goffset));
               if (sgip->table[0] == NULL)
                 {
                   free(sgip->table);
@@ -467,8 +467,8 @@ sgiOpenFile(FILE *file, /* I - File to open */
                 sgip->table[i] = sgip->table[0] + i * sgip->ysize;
               sgip->length    = calloc(sgip->zsize, sizeof(goffset *));
               sgip->length[0] =
-                g_try_malloc ((gsize) sgip->ysize * sgip->zsize *
-                              sizeof (goffset));
+                g_try_malloc0 ((gsize) sgip->ysize * sgip->zsize *
+                               sizeof (goffset));
               for (i = 1; i < sgip->zsize; i ++)
                 sgip->length[i] = sgip->length[0] + i * sgip->ysize;
               break;
-- 
2.55.0

Reply via email to