gpp_maybe
Security update for imagemagick
SUSE-SLE-Module-Development-Tools-15-SP7-2026-851
This update for ImageMagick fixes the following issues: - CVE-2026-24481: Possible Heap Information Disclosure in PSD ZIP Decompression (bsc#1258743). - CVE-2026-24484: denial of service vulnerability via multi-layer nested MVG to SVG conversion (bsc#1258790). - CVE-2026-24485: denial of service via malformed PCD file processing (bsc#1258791). - CVE-2026-25576: Out of bounds read in multiple coders that read raw pixel data (bsc#1258748). - CVE-2026-25637: Denial of Service via crafted image due to memory leak (bsc#1258759). - CVE-2026-25638: Denial of Service due to memory leak in image processing (bsc#1258793). - CVE-2026-25795: Denial of Service due to NULL pointer dereference during temporary file creation failure (bsc#1258792). - CVE-2026-25796: Memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths (bsc#1258757). - CVE-2026-25797: Code injection in various encoders (bsc#1258770). - CVE-2026-25798: NULL Pointer Dereference in ClonePixelCacheRepository via crafted image (bsc#1258787). - CVE-2026-25799: Division-by-Zero in YUV sampling factor validation leads to crash (bsc#1258786). - CVE-2026-25897: Out-of-bounds heap write via integer overflow in sun decoder (bsc#1258799). - CVE-2026-25898: Information disclosure or denial of service via crafted image with invalid pixel index (bsc#1258807). - CVE-2026-25965: Policy bypass through path traversal allows reading restricted content despite secured policy (bsc#1258785). - CVE-2026-25966: Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access (bsc#1258780). - CVE-2026-25967: Stack buffer overflow in FTXT reader via oversized integer field (bsc#1258779). - CVE-2026-25968: MSL attribute stack buffer overflow leads to out of bounds write (bsc#1258776). - CVE-2026-25969: Memory Leak in coders/ashlar.c (bsc#1258775). - CVE-2026-25970: Memory corruption and denial of service via signed integer overflow in SIXEL decoder (bsc#1258802). - CVE-2026-25971: MSL: Stack overflow in ProcessMSLScript (bsc#1258774). - CVE-2026-25982: Heap Out-of-Bounds Read in DCM Decoder (bsc#1258772). - CVE-2026-25983: Denial of service via crafted MSL script (bsc#1258805). - CVE-2026-25985: Memory allocation with excessive without limits in the internal SVG decoder (bsc#1258812). - CVE-2026-25986: Denial of Service via malicious YUV image processing (bsc#1258818). - CVE-2026-25987: Memory disclosure and denial of service via crafted MAP files (bsc#1258821). - CVE-2026-25988: Denial of Service due to memory leak in image processing (bsc#1258810). - CVE-2026-25989: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder (bsc#1258771). - CVE-2026-26066: Infinite loop when writing IPTCTEXT leads to denial of service via crafted profile (bsc#1258769). - CVE-2026-26283: Possible infinite loop in JPEG encoder when using `jpeg: extent` (bsc#1258767). - CVE-2026-26284: Heap overflow in pcd decoder leads to out of bounds read (bsc#1258765). - CVE-2026-26983: Invalid MSL <map> can result in a use after free (bsc#1258763). - CVE-2026-27798: Heap Buffer Over-read in WaveletDenoise when processing small images (bsc#1259018). - CVE-2026-27799: ImageMagick has a heap Buffer Over-read in its DJVU image format handler (bsc#1259017).
-
Release DateMar 9 2026
-
ReferencesBugzilla: 1258743, 1258748, 1258757, 1258759, 1258763, 1258765, 1258767, 1258769, 1258770, 1258771, 1258772, 1258774, 1258775, 1258776, 1258779, 1258780, 1258785, 1258786, 1258787, 1258790, 1258791, 1258792, 1258793, 1258799, 1258802, 1258805, 1258807, 1258810, 1258812, 1258818, 1258821, 1259017, 1259018
CVEs: CVE-2026-24481, CVE-2026-24484, CVE-2026-24485, CVE-2026-25576, CVE-2026-25637, CVE-2026-25638, CVE-2026-25795, CVE-2026-25796, CVE-2026-25797, CVE-2026-25798, CVE-2026-25799, CVE-2026-25897, CVE-2026-25898, CVE-2026-25965, CVE-2026-25966, CVE-2026-25967, CVE-2026-25968, CVE-2026-25969, CVE-2026-25970, CVE-2026-25971, CVE-2026-25982, CVE-2026-25983, CVE-2026-25985, CVE-2026-25986, CVE-2026-25987, CVE-2026-25988, CVE-2026-25989, CVE-2026-26066, CVE-2026-26283, CVE-2026-26284, CVE-2026-26983, CVE-2026-27798, CVE-2026-27799 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 x86_64
-
PackagesImageMagick
Viewer and Converter for Imagesperl-PerlMagick7.1.1.43-150700.3.37.1 lock src
Perl interface for ImageMagick7.1.1.43-150700.3.37.1 lock rpm
Development Tools Module 15.7 aarch64
-
PackagesImageMagick
Viewer and Converter for Imagesperl-PerlMagick7.1.1.43-150700.3.37.1 lock src
Perl interface for ImageMagick7.1.1.43-150700.3.37.1 lock rpm
Development Tools Module 15.7 ppc64le
-
PackagesImageMagick
Viewer and Converter for Imagesperl-PerlMagick7.1.1.43-150700.3.37.1 lock src
Perl interface for ImageMagick7.1.1.43-150700.3.37.1 lock rpm
Development Tools Module 15.7 s390x
-
PackagesImageMagick
Viewer and Converter for Imagesperl-PerlMagick7.1.1.43-150700.3.37.1 lock src
Perl interface for ImageMagick7.1.1.43-150700.3.37.1 lock rpm