Описание
Security update for ImageMagick
This update for ImageMagick fixes the following issues:
- CVE-2026-86420: Denial of Service due to memory budget exhaustion (bsc#1279696).
- CVE-2026-86421: Denial of Service via memory leak in MSL decoder (bsc#1279711).
- CVE-2026-86423: Denial of service via heap-use-after-free in PerlMagick's GetList method (bsc#1279794).
- CVE-2026-86425: Denial of Service due to heap-use-after-free vulnerability (bsc#1279797).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1279696
- SUSE Bug 1279711
- SUSE Bug 1279794
- SUSE Bug 1279797
- SUSE CVE CVE-2026-86420 page
- SUSE CVE CVE-2026-86421 page
- SUSE CVE CVE-2026-86423 page
- SUSE CVE CVE-2026-86425 page
Описание
ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.
Затронутые продукты
Ссылки
- CVE-2026-86420
- SUSE Bug 1279696
Описание
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2026-86421
- SUSE Bug 1279711
Описание
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).
Затронутые продукты
Ссылки
- CVE-2026-86423
- SUSE Bug 1279794
Описание
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).
Затронутые продукты
Ссылки
- CVE-2026-86425
- SUSE Bug 1279797