Arbitrary code execution when opening a specially crafted file (bsc#1275941).
CVE-2026-77219: integer overflow in the PBM/PPM/PGM image loader leads to heap memory content leaks when a crafted
image with large dimensions and an elevated max color index is processed (bsc#1276264).
CVE-2026-79992: improper argument sanitization in TRAMP leads to arbitrary code execution via crafted filenames
(bsc#1275927).