Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Fix CVE-2026-42144: integer overflow. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-45b342f7c1 2026-06-28 01:07:37.246043+00:00 -------------------------------------------------------------------------------- Name : krita Product : Fedora 43 Version : 5.2.16 Release : 2.fc43 URL : https://krita.org Summary : Krita is a sketching and painting program Description : Krita is a sketching and painting program. It was created with the following types of art in mind: - concept art - texture or matte painting - illustrations and comics -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-42144: integer overflow -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Than Ngo - 5.2.16-2 - Fix rhbz#2476570, CVE-2026-42144 integer overflow in PNM size check bypasses memory guard -------------------------------------------------------------------------------- References: [ 1 ] Bug #2476573 - CVE-2026-42144 krita: integer overflow in PNM size check bypasses memory guard (_load_pnm) [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2476573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-45b342f7c1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Update to 6.0.2.1 Fix CVE-2026-42144. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3bb1c72ffd 2026-06-28 00:56:23.048182+00:00 -------------------------------------------------------------------------------- Name : krita Product : Fedora 44 Version : 6.0.2.1 Release : 1.fc44 URL : https://krita.org Summary : Krita is a sketching and painting program Description : Krita is a sketching and painting program. It was created with the following types of art in mind: - concept art - texture or matte painting - illustrations and comics -------------------------------------------------------------------------------- Update Information: Update to 6.0.2.1 Fix CVE-2026-42144 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Than Ngo - 6.0.2.1-1 - Fix rhbz#2481429, Update to 6.0.2.1 - Fix rhbz#2476570, CVE-2026-42144: integer overflow in PNM size check bypasses memory guard * Fri Jun 5 2026 Python Maint - 6.0.1-7 - Rebuilt for Python 3.15 * Sat May 30 2026 Richard Shaw - 6.0.1-6 - Rebuild for OpenColorIO 2.5.2. * Wed May 27 2026 Sandro Mani - 6.0.1-5 - Rebuild (quazip) * Mon May 25 2026 Richard Shaw - 6.0.1-4 - Rebuild for OpenEXR 3.4.12. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2476573 - CVE-2026-42144 krita: integer overflow in PNM size check bypasses memory guard (_load_pnm) [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2476573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3bb1c72ffd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New krita packages are available for Slackware 15.0 to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] krita (SSA:2026-093-02) New krita packages are available for Slackware 15.0 to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/krita-5.0.2-i586-3_slack15.0.txz: Rebuilt. This update fixes a security issue: Heap-based buffer overflow when parsing TGA files. Thanks to pbslxw for the heads-up. For more information, see: https://kde.org/info/security/advisory-20250929-1.txt https://www.cve.org/CVERecord?id=CVE-2025-59820 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/krita-5.0.2-i586-3_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/krita-5.0.2-x86_64-3_slack15.0.txz MD5 signatures: +-------------+ Slackware 15.0 package: e6c6a2224f180c85bf081ba93ab19e61 krita-5.0.2-i586-3_slack15.0.txz Slackware x86_64 15.0 package: 6de3b2e0ed7da333bdb77eab98c1331a krita-5.0.2-x86_64-3_slack15.0.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg krita-5.0.2-i586-3_slack15.0.txz +-----+ . Krita packages for Slackware 15.0 are updated to fix a critical heap-based buffer overflow issue that could lead to security risks.. Krita Security Update, Slackware 15.0 Advisory, Heap Buffer Overflow. . Severity: Critical. LinuxSecurity.com Team
Loading a manipulated TGA file in krita, an image manipulation program, could result in a heap-based buffer overflow in KisTgaImport. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4395-1
An update that solves one vulnerability can now be installed.. # krita-5.2.13-1.1 on GA media Announcement ID: openSUSE-SU-2025:15577-1 Rating: moderate Cross-References: * CVE-2025-59820 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the krita-5.2.13-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * krita 5.2.13-1.1 * krita-devel 5.2.13-1.1 * krita-lang 5.2.13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-59820.html . Krita-5.2.13-1.1 on openSUSE Tumbleweed fixed moderate severity issues with CVE-2025-59820; install updates now!. openSUSE Tumbleweed, Krita update, security issues, system vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.