Opened 12 months ago

Closed 12 months ago

Last modified 8 months ago

#22246 closed enhancement (fixed)

gimp-3.0.6

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version

The release notes for this version can be found at ​https://www.gimp.org/news/2025/10/06/gimp-3-0-6-released/

However, looking over at ​https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home - there are fixes for:

  • CVE-2025-10920: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
  • CVE-2025-10925: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
  • CVE-2025-10934: GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
  • CVE-2025-10924: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability
  • CVE-2025-10923: GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability
  • CVE-2025-10922: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Change History (6)

comment:1 by Douglas R. Reno, 12 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 12 months ago

This one has been a little bit annoying to deal with. Three tests are failing:

 3/21 gimp:app / save-and-export             FAIL            0.79s   killed by signal 5 SIGTRAP
 4/21 gimp:app / single-window-mode          FAIL            0.81s   killed by signal 5 SIGTRAP
 5/21 gimp:app / ui                          FAIL            0.81s   killed by signal 5 SIGTRAP

It generates errors such as:

Bail out! GEGL-FATAL-WARNING: Failed to set operation type gegl:emboss, using a 
passthrough op instead

I did some research on this and found the API documentation for gegl:emboss, and ran "gegl --list-all" to make sure that gegl:emboss was built in. It appears to be built in, and functioning correctly.

The actual problem is documented here: ​https://gitlab.gnome.org/GNOME/gimp/-/issues/14822 - so for now, we'll just note that they fail. Note that this still occurs even with "-D headless-tests=disabled" passed to meson.

comment:3 by Douglas R. Reno, 12 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 32bdc49632926bd26512b578c2a8a10b2a528071

SA-12.4-016 issued

in reply to:  2 comment:4 by Bruce Dubbs, 12 months ago

Replying to Douglas R. Reno:

This one has been a little bit annoying to deal with. Three tests are failing:

[snip]

The actual problem is documented here: ​https://gitlab.gnome.org/GNOME/gimp/-/issues/14822 - so for now, we'll just note that they fail. Note that this still occurs even with "-D headless-tests=disabled" passed to meson.

This kinda begs the question if upstream actually runs their own tests before making a release. If they do, why don't they see the failures? Or if the failures occur for them, why are they ignored?

comment:5 by Douglas R. Reno, 12 months ago

In their CI system, the tests pass - but it's much more minimal of an installation with locked versions of packages and no GUI...

comment:6 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.