This update for gimp fixes the following issues:
Changes in gimp:
Update to 3.0.6:
Security:
Core:
Improved in-GUI release notes' demo script language:
Fixed Alpha to Selection on single layers with no transparency.
Various code is slowly ported to newer code, preparing for GTK4 port (in an unplanned future step):
(Experimental) GEX Format was updated.
Palette import:
Improved filter actions' sensitivity to make sure they are set insensitive when relevant. In particular filters which cannot be run non-destructively (e.g. filters with aux inputs, non-interactive filters and GEGL Graph) must be insensitive when trying to run them on group layers.
Tools:
Graphical User Interface:
Various improvements to window management:
Various CSS improvements for styling of the interface. Some theme leaks were also fixed.
About dialog:
The search popup won't pop up without an image.
Debug/CRITICAL dialog:
While loading images, all widgets in the file dialog are made insensitive, except for the Cancel button and the progress bar.
Welcome dialog:
Plug-ins:
Small Tiles: fix display lag.
CVE-2025-10925: Fix GIMP ILBM file parsing stack-based buffer overflow remote code execution vulnerability. (ZDI-25-914, ZDI-CAN-27793, bsc#1250501)
CVE-2025-10922: Fix GIMP DCM file parsing heap-based buffer overflow remote code execution vulnerability. (ZDI-25-911, ZDI-CAN-27863, bsc#1250497)
CVE-2025-10920: Prevent overflow attack by checking if output >= max, not just output > max. (ZDI-25-909, ZDI-CAN-27684, bsc#1250495)
CVE-2025-10924: Fix integer overflow while parsing FF files. (bsc#1250499)
CVE-2025-2760: A vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. The specific flaw exists within parsing of XWD files. An integer overflow happens before allocating a buffer. This fixed in GIMP 3.0.0. https://www.gimp.org/news/2025/03/16/gimp-3-0-released (bsc#1241690)
{
"binaries": [
{
"gimp": "3.0.6-bp160.1.1",
"gimp-lang": "3.0.6-bp160.1.1",
"libgimpui-3_0-0": "3.0.6-bp160.1.1",
"gimp-extension-goat-excercises": "3.0.6-bp160.1.1",
"gimp-devel": "3.0.6-bp160.1.1",
"libgimp-3_0-0": "3.0.6-bp160.1.1",
"gimp-plugin-python3": "3.0.6-bp160.1.1",
"gimp-plugin-aa": "3.0.6-bp160.1.1",
"gimp-vala": "3.0.6-bp160.1.1"
}
]
}