gpp_maybe
Security update for imagemagick
SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2877
This update for ImageMagick fixes the following issues: - CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read (bsc#1270073). - CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). - CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). - CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). - CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). - CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). - CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). - CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). - CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). - CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). - CVE-2026-42050: stack buffer overflow via a malicious MIFF file (bsc#1265048). - CVE-2026-42326: out-of-bounds read of single byte via malicious IPTC file (bsc#1268092). - CVE-2026-45031: missing check in the PSD decoder allows bypass of the list-length resource policy when decoding a PSD image (bsc#1268094). - CVE-2026-45358: off-by-one error in the meta encoder can lead to an out-of-bounds read of a single byte (bsc#1268102). - CVE-2026-45359: heap buffer overread via invalid `connected-components` value (bsc#1268095). - CVE-2026-45624: performing a polynomial distortion can lead to an out-of-bounds over-read of 24 bytes (bsc#1268096). - CVE-2026-45664: missing check in the MNG coder can lead to excessive resource use and a DoS (bsc#1268101). - CVE-2026-46520: out-of-bounds write when processing multiple images with different dimensions (bsc#1268112). - CVE-2026-46521: missing check when using LZMA compression in the MIFF encoder can lead to an out-of-bounds write (bsc#1268124). - CVE-2026-46522: missing check in the MIFF decoder can lead to a denial of service via crafted MIFF file (bsc#1268126). - CVE-2026-46523: heap use-after-free via a crafted MSL image (bsc#1268125). - CVE-2026-46557: missing depth check can lead to a stack buffer overflow in the fx operation when processing a crafted argument (bsc#1268123). - CVE-2026-46559: incorrect check in the JP2 can lead to a heap buffer overwrite of a single byte when specifying certain options (bsc#1268121). - CVE-2026-46692: heap buffer overwrite in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). - CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117). - CVE-2026-47165: distributed pixel cache was designed to operate without a challenge-response authentication model (bsc#1268114). - CVE-2026-47166: heap buffer overread in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). - CVE-2026-48724: heap buffer underwrite in the Floyd-Steinberg depth dithering (bsc#1268116). - CVE-2026-48734: missing depth or visited-set check can lead to a stack buffer overflow in the MVG decoder (bsc#1268122). - CVE-2026-48994: missing check of a return value in the MAT decoder can lead to a heap buffer overwrite on 32-bit systems (bsc#1268111). - CVE-2026-49218: missing check in the DCM decoder can lead to a DoS (bsc#1268110). - CVE-2026-53460: missing check for maximum memory request in `AcquireAlignedMemory` can lead to an OOM condition (bsc#1268108). - CVE-2026-53461: incorrect loop in the ICON decoder can lead to an out-of-bounds heap write (bsc#1268107). - CVE-2026-53463: passing incorrect arguments in the distort operation can lead to NULL pointer dereference (bsc#1268105). - CVE-2026-53464: providing invalid options to the wand option parser can lead to a memory leak (bsc#1268103). - CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). - CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). - CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). - CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). - CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). - GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640).
-
Release DateJul 13 2026
-
ReferencesBugzilla: 1265048, 1268092, 1268094, 1268095, 1268096, 1268101, 1268102, 1268103, 1268105, 1268107, 1268108, 1268110, 1268111, 1268112, 1268113, 1268114, 1268116, 1268117, 1268120, 1268121, 1268122, 1268123, 1268124, 1268125, 1268126, 1268640, 1268645, 1268878, 1268879, 1268880, 1269063, 1269064, 1270001, 1270002, 1270003, 1270004, 1270073, 1270074, 1270077, 1270079, 1270080, 1271099
CVEs: CVE-2026-40169, CVE-2026-42050, CVE-2026-42326, CVE-2026-45031, CVE-2026-45358, CVE-2026-45359, CVE-2026-45624, CVE-2026-45664, CVE-2026-46520, CVE-2026-46521, CVE-2026-46522, CVE-2026-46523, CVE-2026-46557, CVE-2026-46559, CVE-2026-46692, CVE-2026-46693, CVE-2026-47165, CVE-2026-47166, CVE-2026-48724, CVE-2026-48734, CVE-2026-48994, CVE-2026-49218, CVE-2026-53460, CVE-2026-53461, CVE-2026-53463, CVE-2026-53464, CVE-2026-53466, CVE-2026-53467, CVE-2026-55594, CVE-2026-55595, CVE-2026-55597, CVE-2026-56361, CVE-2026-56363, CVE-2026-56364, CVE-2026-56365, CVE-2026-56367, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56374, CVE-2026-56376, CVE-2026-56379 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Desktop Applications Module 15.7 aarch64
-
PackagesImageMagick
Viewer and Converter for ImagesImageMagick-config-7-SUSE7.1.1.43-150700.3.65.1 lock rpm lock src
SUSE Provided ConfigurationImageMagick-config-7-upstream-limited7.1.1.43-150700.3.65.1 lock rpm
Limited ImageMagick Security PolicyImageMagick-config-7-upstream-open7.1.1.43-150700.3.65.1 lock rpm
Open ImageMagick Security PolicyImageMagick-config-7-upstream-secure7.1.1.43-150700.3.65.1 lock rpm
Secure ImageMagick Security PolicyImageMagick-config-7-upstream-websafe7.1.1.43-150700.3.65.1 lock rpm
Web-safe ImageMagick Security PolicyImageMagick-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C interfacelibMagick++-7_Q16HDRI57.1.1.43-150700.3.65.1 lock rpm
C++ interface runtime library for ImageMagicklibMagick++-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C++ interfacelibMagickCore-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagicklibMagickWand-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagick7.1.1.43-150700.3.65.1 lock rpm
Desktop Applications Module 15.7 ppc64le
-
PackagesImageMagick
Viewer and Converter for ImagesImageMagick-config-7-SUSE7.1.1.43-150700.3.65.1 lock rpm lock src
SUSE Provided ConfigurationImageMagick-config-7-upstream-limited7.1.1.43-150700.3.65.1 lock rpm
Limited ImageMagick Security PolicyImageMagick-config-7-upstream-open7.1.1.43-150700.3.65.1 lock rpm
Open ImageMagick Security PolicyImageMagick-config-7-upstream-secure7.1.1.43-150700.3.65.1 lock rpm
Secure ImageMagick Security PolicyImageMagick-config-7-upstream-websafe7.1.1.43-150700.3.65.1 lock rpm
Web-safe ImageMagick Security PolicyImageMagick-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C interfacelibMagick++-7_Q16HDRI57.1.1.43-150700.3.65.1 lock rpm
C++ interface runtime library for ImageMagicklibMagick++-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C++ interfacelibMagickCore-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagicklibMagickWand-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagick7.1.1.43-150700.3.65.1 lock rpm
Desktop Applications Module 15.7 x86_64
-
PackagesImageMagick
Viewer and Converter for ImagesImageMagick-config-7-SUSE7.1.1.43-150700.3.65.1 lock rpm lock src
SUSE Provided ConfigurationImageMagick-config-7-upstream-limited7.1.1.43-150700.3.65.1 lock rpm
Limited ImageMagick Security PolicyImageMagick-config-7-upstream-open7.1.1.43-150700.3.65.1 lock rpm
Open ImageMagick Security PolicyImageMagick-config-7-upstream-secure7.1.1.43-150700.3.65.1 lock rpm
Secure ImageMagick Security PolicyImageMagick-config-7-upstream-websafe7.1.1.43-150700.3.65.1 lock rpm
Web-safe ImageMagick Security PolicyImageMagick-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C interfacelibMagick++-7_Q16HDRI57.1.1.43-150700.3.65.1 lock rpm
C++ interface runtime library for ImageMagicklibMagick++-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C++ interfacelibMagickCore-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagicklibMagickWand-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagick7.1.1.43-150700.3.65.1 lock rpm
Desktop Applications Module 15.7 s390x
-
PackagesImageMagick
Viewer and Converter for ImagesImageMagick-config-7-SUSE7.1.1.43-150700.3.65.1 lock rpm lock src
SUSE Provided ConfigurationImageMagick-config-7-upstream-limited7.1.1.43-150700.3.65.1 lock rpm
Limited ImageMagick Security PolicyImageMagick-config-7-upstream-open7.1.1.43-150700.3.65.1 lock rpm
Open ImageMagick Security PolicyImageMagick-config-7-upstream-secure7.1.1.43-150700.3.65.1 lock rpm
Secure ImageMagick Security PolicyImageMagick-config-7-upstream-websafe7.1.1.43-150700.3.65.1 lock rpm
Web-safe ImageMagick Security PolicyImageMagick-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C interfacelibMagick++-7_Q16HDRI57.1.1.43-150700.3.65.1 lock rpm
C++ interface runtime library for ImageMagicklibMagick++-devel7.1.1.43-150700.3.65.1 lock rpm
Development files for ImageMagick's C++ interfacelibMagickCore-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagicklibMagickWand-7_Q16HDRI107.1.1.43-150700.3.65.1 lock rpm
C runtime library for ImageMagick7.1.1.43-150700.3.65.1 lock rpm