[parted-devel] parted 3.7.14 alpha build

Brian C. Lane bcl at redhat.com
Thu Sep 17 22:13:59 BST 2026


This is to announce parted-3.7.14, a alpha release.

This will turn into a 3.8 release next week if there are no complaints
before then. This update consists of fixes for 2 CVEs and some bugs
found by the AISLE scan of parted. To my chagrin I backtracked on my
original reluctance to accepting the AI suggested patch for Hurd -- it
has been reviewed by 2 people though.

There have been 20 commits by 4 people in the 23 weeks since 3.7.

See the NEWS below for a brief summary.

Thanks to everyone who has contributed!
The following people contributed changes to this release:

  Brian C. Lane (17)
  Colin Watson (1)
  Victor Couty (1)

Brian
 [on behalf of the parted maintainers]
==================================================================

Here is the GNU parted home page:
    https://gnu.org/s/parted/

Here are the compressed sources and a GPG detached signature:
  https://alpha.gnu.org/gnu/parted/parted-3.7.14.tar.xz
  https://alpha.gnu.org/gnu/parted/parted-3.7.14.tar.xz.sig

Use a mirror for higher download bandwidth:
  https://www.gnu.org/order/ftp.html

Here are the SHA256 and SHA3-256 checksums:

  File: parted-3.7.14.tar.xz
  SHA256 sum:   4d8320a94b49840bdce4edb8e5c95427985a27724e7be97369df1044e28f56ac
  SHA3-256 sum: 5b3a2994bdaad0e8229ed98cfe3a6ead745eef7ad1e0111a02323967a90a05e5

Verify the SHA256 checksum with either sha256sum, sha256, or
'shasum -a 256'.

Verify the SHA3-256 checksum with 'cksum -a sha3 -l 256'
from coreutils-9.8.

Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact.  First, be sure to download both the .sig file
and the corresponding tarball.  Then, run a command like this:

  gpg --verify parted-3.7.14.tar.xz.sig parted-3.7.14.tar.xz

The signature should match the fingerprint of the following key:

  pub   ed25519/FF9868A2D488A5A9 2026-04-14 [SC]
        Key fingerprint = 872F 3A8A 0B84 905A FFBC  8766 FF98 68A2 D488 A5A9
  uid                 [ultimate] Brian C. Lane <bcl at redhat.com>

If that command fails because you don't have the required public key,
or that public key has expired, try the following commands to retrieve
or refresh it, and then rerun the 'gpg --verify' command.

  gpg --locate-external-key bcl at redhat.com

  gpg --recv-keys FF9868A2D488A5A9

  wget -q -O- 'https://savannah.gnu.org/project/release-gpgkeys.php?group=parted&download=1' | gpg --import -

As a last resort to find the key, you can try the official GNU
keyring:

  wget -q https://ftp.gnu.org/gnu/gnu-keyring.gpg
  gpg --keyring gnu-keyring.gpg --verify parted-3.7.14.tar.xz.sig parted-3.7.14.tar.xz

This release is based on the parted git repository, available as

  git clone https://https.git.savannah.gnu.org/git/parted.git

with commit f06593df5aef43817ab75d5ec9bf11975d9b16b6 tagged as v3.7.14.

For a summary of changes and contributors, see:

  https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=shortlog;h=v3.7.14

or run this command from a git-cloned parted directory:

  git shortlog v3.7.13..v3.7.14

This release was bootstrapped with the following tools:
  Autoconf 2.72
  Automake 1.18.1
  Gettext 0.25.1
  Gnulib 2026-09-16 bc4c32a353bde2edd2ec3a93b66ec99f717f378d
  Gperf 3.2.1

NEWS

* Noteworthy changes in release 3.7.14 (2026-09-17) [alpha]

** Bug Fixes

  hurd: Fix gnu_read problems with block size > 512b

* Noteworthy changes in release 3.7.13 (2026-09-14) [alpha]

** New Features

  Add support for ExFAT filesystem

** Bug Fixes

  build: mark functions with const attribute, per gcc warnings

  Cleanup zero as null pointer constant warnings

  Fix 2 CVEs - CVE-2026-89085 and CVE-2026-89088

  Add PED_ASSERT protection for 32bit build filesystem resize

  fdasd: Make sure data set name is positive

  parted: Fix partition number allocation in do_print

-- 
Brian C. Lane (PST8PDT) - weldr.io - lorax - parted - pykickstart - osbuild




More information about the parted-devel mailing list