Skip to main content

Security update for ImageMagick

0
High
Published: 07/22/2026 (07/22/2026, 19:01:21 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This security update for ImageMagick addresses multiple vulnerabilities including memory leaks, arbitrary command injection, heap buffer over-write, policy bypass, use-after-free, and information disclosure. The flaws affect various components such as the ASHLAR coder, SVG decoder, X11 import, script operations, freetype initialization, and multiple image encoders and decoders. These issues could lead to resource exhaustion, unauthorized command execution, memory corruption, bypass of security policies, and leakage of sensitive information. The update fixes these issues to improve the security and stability of ImageMagick.

Affected software

Affected versions
SUSEaarch64ImageMagick-7.1.2.0-160000.13.1.aarch64ImageMagick-devel-7.1.2.0-160000.13.1.aarch64ImageMagick-extra-7.1.2.0-160000.13.1.aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 02:55:33 UTC

Technical Analysis

The update for ImageMagick fixes a range of security issues: CVE-2026-56375 addresses a possible memory leak in the ASHLAR coder when an action fails; CVE-2026-56379 patches an arbitrary MVG drawing command injection vulnerability via the SVG decoder when processing crafted SVG files; CVE-2026-61464 resolves a heap buffer over-write in X11 import triggered by crafted window titles; CVE-2026-61859 fixes a policy bypass in script operations due to missing checks; CVE-2026-61860 mitigates a use-after-free condition when freetype initialization fails; CVE-2026-61862 closes an information disclosure issue when printing profiles with debug enabled; and CVE-2026-61863 through CVE-2026-61872 address multiple memory leaks in various encoders and decoders triggered by allocation failures or invalid input. These collectively enhance the security posture of ImageMagick by preventing potential exploitation vectors related to memory management, command injection, and policy enforcement.

Potential Impact

The vulnerabilities could lead to memory leaks causing resource exhaustion, arbitrary command injection allowing execution of unauthorized drawing commands, heap buffer over-write potentially causing crashes or code execution, policy bypass enabling unauthorized script operations, use-after-free leading to memory corruption, and information disclosure revealing sensitive profile data. These impacts could affect the confidentiality, integrity, and availability of systems using vulnerable versions of ImageMagick.

Mitigation Recommendations

A security update is available that fixes all listed vulnerabilities. Users and administrators should apply the official ImageMagick update provided by the SUSE Product Security Team to remediate these issues. No additional mitigation steps are indicated beyond applying the update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:21426-1
Cve Count
15
Additional Cves
["CVE-2026-56379","CVE-2026-61464","CVE-2026-61859","CVE-2026-61860","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61871","CVE-2026-61872"]

Threat ID: 6aab496755bf5e2cf5990d03

Added to database: 09/17/2026, 01:59:03 UTC

Last enriched: 09/17/2026, 02:55:33 UTC

Last updated: 09/17/2026, 02:55:33 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses