summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGyorgy Sarvari <skandigraun@gmail.com>2026-03-09 19:21:00 +0100
committerGyorgy Sarvari <skandigraun@gmail.com>2026-03-09 19:22:41 +0100
commit68a9fca0d806dfd13c68ffb4a7199d38feffee7a (patch)
treea20c40abece7fa28d24d5f0d6f52c908da502651
parent9cc3662befa738c400cdaf5d64674ebaf0582d97 (diff)
downloadmeta-openembedded-68a9fca0d806dfd13c68ffb4a7199d38feffee7a.tar.gz
gimp: patch CVE-2023-44443 and CVE-2023-44444
Details: https://nvd.nist.gov/vuln/detail/CVE-2023-44443 https://nvd.nist.gov/vuln/detail/CVE-2023-44444 The relevant upstream issues: https://gitlab.gnome.org/GNOME/gimp/-/issues/10072 https://gitlab.gnome.org/GNOME/gimp/-/issues/10071 For the backport, upstream has merged the two patches into one, solving both CVEs. That patch is in this change. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
-rw-r--r--meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch47
-rw-r--r--meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb1
2 files changed, 48 insertions, 0 deletions
diff --git a/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch b/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch
new file mode 100644
index 0000000000..c92aaa24a9
--- /dev/null
+++ b/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch
@@ -0,0 +1,47 @@
1From 8a8c3fe7cdb498d05d8e61e6b0f36d9a314caa62 Mon Sep 17 00:00:00 2001
2From: Alx Sa <cmyk.student@gmail.com>
3Date: Sat, 23 Sep 2023 20:40:18 +0000
4Subject: [PATCH] plug-ins: Fix vulnerabilities in file-psp
5
6Backports commits e1bfd871 and 96f536a3
7from master
8
9CVE: CVE-2023-44443 CVE-2023-44444
10Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/gimp/-/commit/ef12c0a90752a06d4c465a768d052b07f5e8a8a0]
11Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
12---
13 plug-ins/common/file-psp.c | 13 +++++++++++--
14 1 file changed, 11 insertions(+), 2 deletions(-)
15
16diff --git a/plug-ins/common/file-psp.c b/plug-ins/common/file-psp.c
17index c0f3480..6a6b93d 100644
18--- a/plug-ins/common/file-psp.c
19+++ b/plug-ins/common/file-psp.c
20@@ -1128,8 +1128,17 @@ read_color_block (FILE *f,
21 }
22
23 color_palette_entries = GUINT32_FROM_LE (entry_count);
24+ /* TODO: GIMP currently only supports a maximum of 256 colors
25+ * in an indexed image. If this changes, we can change this check */
26+ if (color_palette_entries > 256)
27+ {
28+ g_set_error (error, G_FILE_ERROR, G_FILE_ERROR_FAILED,
29+ _("Error: Unsupported palette size"));
30+ return -1;
31+ }
32+
33 /* psp color palette entries are stored as RGBA so 4 bytes per entry
34- where the fourth bytes is always zero */
35+ * where the fourth bytes is always zero */
36 pal_size = color_palette_entries * 4;
37 color_palette = g_malloc (pal_size);
38 if (fread (color_palette, pal_size, 1, f) < 1)
39@@ -1498,7 +1507,7 @@ read_channel_data (FILE *f,
40 else
41 endq = q + line_width * height;
42
43- buf = g_malloc (127);
44+ buf = g_malloc (128);
45 while (q < endq)
46 {
47 fread (&runcount, 1, 1, f);
diff --git a/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb b/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb
index 8eb36e7d8f..df5d395d94 100644
--- a/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb
+++ b/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb
@@ -50,6 +50,7 @@ SRC_URI = "https://download.gimp.org/pub/${BPN}/v${SHPV}/${BP}.tar.bz2 \
50 file://CVE-2022-32990-3.patch \ 50 file://CVE-2022-32990-3.patch \
51 file://CVE-2023-44441.patch \ 51 file://CVE-2023-44441.patch \
52 file://CVE-2023-44442.patch \ 52 file://CVE-2023-44442.patch \
53 file://CVE-2023-44443_CVE-2023-44444.patch \
53 " 54 "
54SRC_URI[sha256sum] = "88815daa76ed7d4277eeb353358bafa116cd2fcd2c861d95b95135c1d52b67dc" 55SRC_URI[sha256sum] = "88815daa76ed7d4277eeb353358bafa116cd2fcd2c861d95b95135c1d52b67dc"
55 56