Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issues
- CVE-2026-31853: heap buffer overflow leads to crash in the SFW decoder of 32-bit systems when processing extremely large images (bsc#1259528).
- CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048).
Список пакетов
SUSE Linux Enterprise Server 15 SP6-LTSS
ImageMagick-7.1.1.21-150600.3.60.1
ImageMagick-config-7-SUSE-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.60.1
ImageMagick-devel-7.1.1.21-150600.3.60.1
libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.60.1
libMagick++-devel-7.1.1.21-150600.3.60.1
libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.60.1
libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.60.1
perl-PerlMagick-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
ImageMagick-7.1.1.21-150600.3.60.1
ImageMagick-config-7-SUSE-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.60.1
ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.60.1
ImageMagick-devel-7.1.1.21-150600.3.60.1
libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.60.1
libMagick++-devel-7.1.1.21-150600.3.60.1
libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.60.1
libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.60.1
perl-PerlMagick-7.1.1.21-150600.3.60.1
Ссылки
- Link for SUSE-SU-2026:2022-1
- E-Mail link for SUSE-SU-2026:2022-1
- SUSE Security Ratings
- SUSE Bug 1259528
- SUSE Bug 1265048
- SUSE CVE CVE-2026-31853 page
- SUSE CVE CVE-2026-42050 page
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large images. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.60.1
Ссылки
- CVE-2026-31853
- SUSE Bug 1259528
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability is fixed in 7.1.2-21 and 6.9.13-46.
Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-SUSE-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.60.1
SUSE Linux Enterprise Server 15 SP6-LTSS:ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.60.1
Ссылки
- CVE-2026-42050
- SUSE Bug 1265048