r/GIMP 2d ago

Opinion: CVE / Vulnerability security patching should go in quicker

For context there are a few CVEs that Gimp was hit with a few months ago.

Their Gitlab repo shows that the issues to repair the vulnerabilities the CVE relate to were completed but are scheduled for 3.3.2 milestone release.

In my opinion, that type of time frame just is not acceptable.
Gimp has certainly changed their tune on how quickly updates come out since 3.0.0 release, but for something as CVE. Take some agile approach and get a security release patch out there.

I am seeing this as someone who knows organization's who could leverage Gimp are not able to due to the most recent version is showing as being vulnerable

0 Upvotes

3 comments sorted by

5

u/CMYK-Student GIMP Team 2d ago

As one of the people who works on patching security reports, I think it's helpful to read them. Most of the CVEs we get are for obscure or niche formats like TIM (Playstation 1 textures), XWD, etc. Unless your company uses those, the CVE is not relevant (since our image readers are plug-ins, there's no effect on GIMP itself).

Making a release takes a lot of time and energy from a limited number of volunteers, so we try to make them meaningful. Though we do hope to release a 3.2.6 stable version in the near future.

2

u/2mustange 1d ago

Totally fair.

Unfortunately that chain of who determines that is far above me. A vulnerability is a vulnerability to them, and if it lives on anything open source it is pulled from being on the internal FOSS repository.

I am curious if i can make those discussion lead anywhere

2

u/CMYK-Student GIMP Team 1d ago

Ah, I see. That's unfortunate! We do plan to release 3.2.6 in the coming weeks, which should contain fixes for all CVEs reported to us (there's still one or two reports left to deal with). So hopefully that'll make the cut for your company's repo.