Opened 6 months ago

Closed 6 months ago

#23069 closed enhancement (fixed)

gimp-3.2.2

Reported by: Xi Ruoyao Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New patch version.

For some reason the currency doesn't report it??

Change History (10)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → elevated

​https://www.gimp.org/news/2026/03/28/gimp-3-2-2-released/ has the release notes for it

Unfortunately though I must report that this comes with security fixes. We've had a lot of those lately :)

No CVEs assigned yet as I suspect it's still too early, but the bug reports upstream can be found at:

These come from ​https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home

comment:2 by Douglas R. Reno, 6 months ago

Note that I will wait on filing an SA until we have CVEs as those have been requested.

comment:3 by Bruce Dubbs, 6 months ago

We had gimp set to 'manual' due to upstream problems. Those are fixed now and I've restored the currency so it works again.

comment:4 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:5 by Joe Locash, 6 months ago

Overview of Changes from GIMP 3.2.0 to GIMP 3.2.2
=================================================

Core:

  - We removed support for a separate folder for loading 32-bit binaries
    on 64-bit Windows. This was being used for core plug-ins for the
    TWAIN plug-in only.
  - Various fixes related to the new non-destructive layer types, or to
    non-destructive layer effects.
  - More robust handling of Procreate and SwatchBooker palettes.
  - Fix scaling paths when importing SVG as paths.
  - We now support reading the documentation being installed in the user
    config directory in the `help/` subdirectory.
  - Histogram dialog: the unique color count feature now takes into
    account any selection.

Graphical User Interface:

  - Theme fixes.
  - Various text fixed for better localization.
  - Display the "Tab" shortcut for the "Hide Docks" action, even though
    it is not a real global shortcut (it only works on the canvas).
  - Metadata Rotation import dialog: you can now click the preview for
    Original and Rotated images in the Metadata Rotation Import Dialog,
    and have it open the image rotated as shown in the preview.

Plug-Ins:

  - Tile: carry over the source image's profile to the newly created
    image.
  - Improve support of: FITS, TIM, PAA, ICNS, PVR, SFW, JIF, PSP, PSD

Translations:

  - Serbian Cyrillic now has upstream support in InnoSetup (in their
    "Unofficial" list still, which means it is less verified). Our
    installer now has Serbian Cyrillic localization too.

Build:

  - NM environment variable is now used in priority for the `nm` tool
    used for the build. This check is stored from configure-time
    environment.
  - Windows x86 32-bit pipeline has now been decommissioned from our CI.
    This implies that 32-bit builds won't be available anymore in our
    Windows installer, just as was already the case on the Windows Store.
  - Meson build:
    * New boolean option -Dtwain-unmaintained: this puts our TWAIN
      plug-in behind a disabled-by-default flag, because this plug-in
      only made sense in 32-bit. The next step will be to replace it by
      a WIA plug-in.
    * Option -Dwin32-32bits-dll-folder removed.
  - GIMP can now be built fully without patches on macOS. The in-house
    macOS build is slowly moving to become our main CI for this OS and
    for making the release DMGs.
  - Snap: enable MIDI (Alsa) support.
  - AppImage: enable "Send by email".

Fixed at 9a96a72433. Leaving open for SA.

comment:6 by Bruce Dubbs, 6 months ago

Owner: changed from Joe Locash to Douglas R. Reno
Status: assigned → new

comment:7 by Bruce Dubbs, 6 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory

comment:8 by Douglas R. Reno, 6 months ago

The CVEs have been assigned finally! Proceeding with a security shortly...

comment:9 by Douglas R. Reno, 6 months ago

CVEs now include... CVE-2026-4887, CVE-2026-4150, CVE-2026-4151, CVE-2026-4152, CVE-2026-4153, CVE-2026-4154, CVE-2026-40915, CVE-2026-40916, CVE-2026-40917, CVE-2026-40918, CVE-2026-40919, and CVE-2026-6384

comment:10 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-050 issued.

Note: See TracTickets for help on using tickets.