Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issues
- CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read (bsc#1270073).
- CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074).
- CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077).
- CVE-2026-55595: providing invalid arguments to the
connected-componentsoption can lead to an infinite loop (bsc#1270079). - CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080).
- CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001).
- CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002).
- CVE-2026-56364: memory leak in
LoadOpenCLDeviceBenchmarkfunction when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). - CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing
ftxt:format(bsc#1271099). - CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).
- GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1268640
- SUSE Bug 1268878
- SUSE Bug 1270001
- SUSE Bug 1270002
- SUSE Bug 1270003
- SUSE Bug 1270073
- SUSE Bug 1270074
- SUSE Bug 1270077
- SUSE Bug 1270079
- SUSE Bug 1270080
- SUSE Bug 1271099
- SUSE CVE CVE-2026-53466 page
- SUSE CVE CVE-2026-53467 page
- SUSE CVE CVE-2026-55594 page
- SUSE CVE CVE-2026-55595 page
- SUSE CVE CVE-2026-55597 page
- SUSE CVE CVE-2026-56361 page
- SUSE CVE CVE-2026-56363 page
- SUSE CVE CVE-2026-56364 page
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Затронутые продукты
Ссылки
- CVE-2026-53466
- SUSE Bug 1270073
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Затронутые продукты
Ссылки
- CVE-2026-53467
- SUSE Bug 1270074
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Затронутые продукты
Ссылки
- CVE-2026-55594
- SUSE Bug 1270077
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.
Затронутые продукты
Ссылки
- CVE-2026-55595
- SUSE Bug 1270079
Описание
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26.
Затронутые продукты
Ссылки
- CVE-2026-55597
- SUSE Bug 1270080
Описание
ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.
Затронутые продукты
Ссылки
- CVE-2026-56361
- SUSE Bug 1270001
Описание
ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash.
Затронутые продукты
Ссылки
- CVE-2026-56363
- SUSE Bug 1270002
Описание
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
Затронутые продукты
Ссылки
- CVE-2026-56364
- SUSE Bug 1270003
Описание
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.
Затронутые продукты
Ссылки
- CVE-2026-56374
- SUSE Bug 1271099
Описание
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
Затронутые продукты
Ссылки
- CVE-2026-56379
- SUSE Bug 1268878