Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21911-1

Опубликовано: 22 сент. 2026
Источник: suse-cvrf

Описание

Security update for ImageMagick

This update for ImageMagick fixes the following issues:

  • CVE-2026-86420: Denial of Service due to memory budget exhaustion (bsc#1279696).
  • CVE-2026-86421: Denial of Service via memory leak in MSL decoder (bsc#1279711).
  • CVE-2026-86423: Denial of service via heap-use-after-free in PerlMagick's GetList method (bsc#1279794).
  • CVE-2026-86425: Denial of Service due to heap-use-after-free vulnerability (bsc#1279797).

Список пакетов

openSUSE Leap 16.0
ImageMagick-7.1.2.0-160000.15.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.15.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.15.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.15.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.15.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.15.1
ImageMagick-devel-7.1.2.0-160000.15.1
ImageMagick-doc-7.1.2.0-160000.15.1
ImageMagick-extra-7.1.2.0-160000.15.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.15.1
libMagick++-devel-7.1.2.0-160000.15.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.15.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.15.1
perl-PerlMagick-7.1.2.0-160000.15.1

Описание

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.15.1

Ссылки

Описание

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.15.1

Ссылки

Описание

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.15.1

Ссылки

Описание

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).


Затронутые продукты
openSUSE Leap 16.0:ImageMagick-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-SUSE-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-limited-7.1.2.0-160000.15.1
openSUSE Leap 16.0:ImageMagick-config-7-upstream-open-7.1.2.0-160000.15.1

Ссылки
Уязвимость openSUSE-SU-2026:21911-1