GIMP 3.0.8 available

The update fixes multiple security vulnerabilities and a few long-standing annoyances.

The open-source image editor GIMP has received an update to version 3.0.8, addressing a number of bugs and closing several potentially serious security vulnerabilities. In short: if you use GIMP, updating is a very good idea.

GIMP, short for GNU Image Manipulation Program, has been around since 1998 and runs on Linux, Windows, macOS, and more. What started as a student project has long since grown into a capable, professional-grade image editing tool and with that maturity comes the occasional need for security cleanups.

Version 3.0.8 is a maintenance and security release, and also something of a bridge on the road to the upcoming GIMP 3.2. According to the release notes, the development team fixed multiple security vulnerabilities, most of them hiding in image import filters. In the worst case, specially crafted image files from untrusted sources could be used to inject or execute code—proof that even opening an image isn't always as harmless as it sounds.

Some of these issues were flagged by Trend Micro's Zero Day Initiative (ZDI), which identified exploitable flaws in various plugins. Others were reported independently and affected formats such as ICO files or PaintShop Pro (PSP) images. Several of these fixes had already appeared in pre-release versions of GIMP 3.2 and have now been rolled into the stable 3.0.8 release.

Another noteworthy fix involves the librsvg library. A vulnerability in earlier versions could be exploited using specially crafted SVG files to bypass NTLM authentication. GIMP 3.0.8 ships with librsvg 2.61.3, which closes that particular door.

That said, most of the changes in this update aren't about security at all—they’re about quality of life. One example: users with large font collections may have noticed painfully slow startup times. The developers have revisited their approach here, ensuring that images are only loaded after fonts are fully initialized. This avoids rare but annoying issues where files try to access fonts that aren't ready yet.

Fin the complete release notes here.

about author