diff options
| author | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-03-09 19:21:00 +0100 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2026-03-09 19:22:41 +0100 |
| commit | 68a9fca0d806dfd13c68ffb4a7199d38feffee7a (patch) | |
| tree | a20c40abece7fa28d24d5f0d6f52c908da502651 | |
| parent | 9cc3662befa738c400cdaf5d64674ebaf0582d97 (diff) | |
| download | meta-openembedded-68a9fca0d806dfd13c68ffb4a7199d38feffee7a.tar.gz | |
gimp: patch CVE-2023-44443 and CVE-2023-44444
Details: https://nvd.nist.gov/vuln/detail/CVE-2023-44443
https://nvd.nist.gov/vuln/detail/CVE-2023-44444
The relevant upstream issues:
https://gitlab.gnome.org/GNOME/gimp/-/issues/10072
https://gitlab.gnome.org/GNOME/gimp/-/issues/10071
For the backport, upstream has merged the two patches
into one, solving both CVEs. That patch is in this change.
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
| -rw-r--r-- | meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch | 47 | ||||
| -rw-r--r-- | meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb | 1 |
2 files changed, 48 insertions, 0 deletions
diff --git a/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch b/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch new file mode 100644 index 0000000000..c92aaa24a9 --- /dev/null +++ b/meta-gnome/recipes-gimp/gimp/gimp/CVE-2023-44443_CVE-2023-44444.patch | |||
| @@ -0,0 +1,47 @@ | |||
| 1 | From 8a8c3fe7cdb498d05d8e61e6b0f36d9a314caa62 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Alx Sa <cmyk.student@gmail.com> | ||
| 3 | Date: Sat, 23 Sep 2023 20:40:18 +0000 | ||
| 4 | Subject: [PATCH] plug-ins: Fix vulnerabilities in file-psp | ||
| 5 | |||
| 6 | Backports commits e1bfd871 and 96f536a3 | ||
| 7 | from master | ||
| 8 | |||
| 9 | CVE: CVE-2023-44443 CVE-2023-44444 | ||
| 10 | Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/gimp/-/commit/ef12c0a90752a06d4c465a768d052b07f5e8a8a0] | ||
| 11 | Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com> | ||
| 12 | --- | ||
| 13 | plug-ins/common/file-psp.c | 13 +++++++++++-- | ||
| 14 | 1 file changed, 11 insertions(+), 2 deletions(-) | ||
| 15 | |||
| 16 | diff --git a/plug-ins/common/file-psp.c b/plug-ins/common/file-psp.c | ||
| 17 | index c0f3480..6a6b93d 100644 | ||
| 18 | --- a/plug-ins/common/file-psp.c | ||
| 19 | +++ b/plug-ins/common/file-psp.c | ||
| 20 | @@ -1128,8 +1128,17 @@ read_color_block (FILE *f, | ||
| 21 | } | ||
| 22 | |||
| 23 | color_palette_entries = GUINT32_FROM_LE (entry_count); | ||
| 24 | + /* TODO: GIMP currently only supports a maximum of 256 colors | ||
| 25 | + * in an indexed image. If this changes, we can change this check */ | ||
| 26 | + if (color_palette_entries > 256) | ||
| 27 | + { | ||
| 28 | + g_set_error (error, G_FILE_ERROR, G_FILE_ERROR_FAILED, | ||
| 29 | + _("Error: Unsupported palette size")); | ||
| 30 | + return -1; | ||
| 31 | + } | ||
| 32 | + | ||
| 33 | /* psp color palette entries are stored as RGBA so 4 bytes per entry | ||
| 34 | - where the fourth bytes is always zero */ | ||
| 35 | + * where the fourth bytes is always zero */ | ||
| 36 | pal_size = color_palette_entries * 4; | ||
| 37 | color_palette = g_malloc (pal_size); | ||
| 38 | if (fread (color_palette, pal_size, 1, f) < 1) | ||
| 39 | @@ -1498,7 +1507,7 @@ read_channel_data (FILE *f, | ||
| 40 | else | ||
| 41 | endq = q + line_width * height; | ||
| 42 | |||
| 43 | - buf = g_malloc (127); | ||
| 44 | + buf = g_malloc (128); | ||
| 45 | while (q < endq) | ||
| 46 | { | ||
| 47 | fread (&runcount, 1, 1, f); | ||
diff --git a/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb b/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb index 8eb36e7d8f..df5d395d94 100644 --- a/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb +++ b/meta-gnome/recipes-gimp/gimp/gimp_2.10.30.bb | |||
| @@ -50,6 +50,7 @@ SRC_URI = "https://download.gimp.org/pub/${BPN}/v${SHPV}/${BP}.tar.bz2 \ | |||
| 50 | file://CVE-2022-32990-3.patch \ | 50 | file://CVE-2022-32990-3.patch \ |
| 51 | file://CVE-2023-44441.patch \ | 51 | file://CVE-2023-44441.patch \ |
| 52 | file://CVE-2023-44442.patch \ | 52 | file://CVE-2023-44442.patch \ |
| 53 | file://CVE-2023-44443_CVE-2023-44444.patch \ | ||
| 53 | " | 54 | " |
| 54 | SRC_URI[sha256sum] = "88815daa76ed7d4277eeb353358bafa116cd2fcd2c861d95b95135c1d52b67dc" | 55 | SRC_URI[sha256sum] = "88815daa76ed7d4277eeb353358bafa116cd2fcd2c861d95b95135c1d52b67dc" |
| 55 | 56 | ||
