Security update for ImageMagick
This update for ImageMagick fixes the following issues Security issues: - CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). - CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092). - CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). - CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). - CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095). - CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096). - CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101). - CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). - CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). - CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). - CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). - CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). - CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). - CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). - CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117). - CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). - CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). - CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering (bsc#1268116). - CVE-2026-48733: Infinite Loop in subimage-search with crafted image (bsc#1268119). - CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). - CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). - CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). - CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). - CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). - CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). - CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). - CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out- of-bounds read (bsc#1268645). - CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). - CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). - CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). - CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). Non security issue: - ImageMagick update 7.1.2.0-160000.9.1 is broken for softlinks (bsc#1265373).
Security update for ImageMagick
Description
This update for ImageMagick fixes the following issues Security issues: - CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). - CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092). - CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). - CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). - CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095). - CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096). - CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101). - CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). - CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). - CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). - CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). - CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). - CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). - CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). - CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117). - CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). - CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). - CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering (bsc#1268116). - CVE-2026-48733: Infinite Loop in subimage-search with crafted image (bsc#1268119). - CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). - CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). - CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). - CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). - CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). - CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). - CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). - CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out- of-bounds read (bsc#1268645). - CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). - CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). - CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). - CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). Non security issue: - ImageMagick update 7.1.2.0-160000.9.1 is broken for softlinks (bsc#1265373).
Affected software
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21071-1
- Cve Count
- 32
- Additional Cves
- ["CVE-2026-42050","CVE-2026-42326","CVE-2026-45031","CVE-2026-45358","CVE-2026-45359","CVE-2026-45624","CVE-2026-45664","CVE-2026-46520","CVE-2026-46521","CVE-2026-46522","CVE-2026-46523","CVE-2026-46557","CVE-2026-46559","CVE-2026-46692","CVE-2026-46693","CVE-2026-47165","CVE-2026-47166","CVE-2026-48724","CVE-2026-48733","CVE-2026-48734","CVE-2026-48994","CVE-2026-49218","CVE-2026-53460","CVE-2026-53461","CVE-2026-53463","CVE-2026-53464","CVE-2026-56367","CVE-2026-56368","CVE-2026-56370","CVE-2026-56371","CVE-2026-56376"]
Threat ID: 6aab497855bf5e2cf5990e42
Added to database: 09/17/2026, 01:59:20 UTC
Last updated: 09/17/2026, 02:02:24 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.