Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20606-1

Опубликовано: 22 апр. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues:

  • CVE-2026-32259: stack out-of-bounds write due to a memory allocation failure in the sixel encoder can lead to a crash (bsc#1259612).
  • CVE-2026-32636: out-of-bounds write of a single zero byte due to bug the NewXMLTree method can lead to denial of service (bsc#1259872).
  • CVE-2026-33535: out-of-bounds write of a zero byte in X11 display interaction path can lead to a crash (bsc#1260874).
  • CVE-2026-33536: stack out-of-bounds write due to incorrect return value on certain platforms can lead to a denial of service (bsc#1260879).
  • CVE-2026-33899: out-of-bounds write of single zero byte in XML parsing can lead to a denial of service (bsc#1262154).
  • CVE-2026-33900: heap out-of-bounds write due to integer truncation in viff encoder can lead to a crash (bsc#1262156).
  • CVE-2026-33901: heap buffer overflow in the MVG decoder can lead to memory corruption or a crash (bsc#1262155).
  • CVE-2026-33902: stack buffer overflow in the FX expression parser can lead to a process crash (bsc#1262153).
  • CVE-2026-33905: out-of-bounds read in -sample operation can lead to a denial of service (bsc#1262097).
  • CVE-2026-33908: recursive execution with no depth limit imposed when processing XML files can lead to resource exhaustion and a denial of service (bsc#1262152).
  • CVE-2026-34238: heap buffer overflow due to integer overflow in the despeckle operation can lead to a denial of service (bsc#1262147).
  • CVE-2026-40169: out-of-bounds heap write when processing a crafted image and writing a YAML or JSON output can lead to a crash (bsc#1262150).
  • CVE-2026-40183: heap out-of-bounds write in the JXL encoder can lead to a denial of service (bsc#1262145).
  • CVE-2026-40310: heap out-of-bounds write in the JP2 encoder can lead to a denial of service (bsc#1262148).
  • CVE-2026-40311: heap use-after-free when reading and printing values from an invalid XMP profile can lead to a denial of service (bsc#1262146).
  • CVE-2026-40312: off-by-one error in the MSL decoder can lead to a crash (bsc#1262149).

Список пакетов

openSUSE Leap 16.0
ImageMagick-7.1.2.0-160000.8.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.8.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.8.1
ImageMagick-devel-7.1.2.0-160000.8.1
ImageMagick-doc-7.1.2.0-160000.8.1
ImageMagick-extra-7.1.2.0-160000.8.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.8.1
libMagick++-devel-7.1.2.0-160000.8.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.8.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.8.1
perl-PerlMagick-7.1.2.0-160000.8.1

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a buffer on the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, an integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.8.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.8.1

Ссылки
Уязвимость openSUSE-SU-2026:20606-1