openSUSE-SU-2026:21291-1: important: Security update for ImageMagick
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for imagemagick
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21291-1
Rating: important
References:
* bsc#1268640
* bsc#1268878
* bsc#1270001
* bsc#1270002
* bsc#1270003
* bsc#1270073
* bsc#1270074
* bsc#1270077
* bsc#1270079
* bsc#1270080
* bsc#1271099
Cross-References:
* CVE-2026-53466
* CVE-2026-53467
* CVE-2026-55594
* CVE-2026-55595
* CVE-2026-55597
* CVE-2026-56361
* CVE-2026-56363
* CVE-2026-56364
* CVE-2026-56374
* CVE-2026-56379
CVSS scores:
* CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 10 vulnerabilities and has 11 bug fixes can now be installed.
Description:
This update for ImageMagick fixes the following issues
- CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read
(bsc#1270073).
- CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure
(bsc#1270074).
- CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is
provided (bsc#1270077).
- CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop
(bsc#1270079).
- CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080).
- CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001).
- CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application
crash (bsc#1270002).
- CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML
files
with unclosed device elements (bsc#1270003).
- CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing
`ftxt:format` (bsc#1271099).
- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG
files (bsc#1268878).
- GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1202=1
Package List:
- openSUSE Leap 16.0:
ImageMagick-7.1.2.0-160000.11.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1
ImageMagick-devel-7.1.2.0-160000.11.1
ImageMagick-doc-7.1.2.0-160000.11.1
ImageMagick-extra-7.1.2.0-160000.11.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1
libMagick++-devel-7.1.2.0-160000.11.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1
perl-PerlMagick-7.1.2.0-160000.11.1
References:
* https://www.suse.com/security/cve/CVE-2026-53466.html
* https://www.suse.com/security/cve/CVE-2026-53467.html
* https://www.suse.com/security/cve/CVE-2026-55594.html
* https://www.suse.com/security/cve/CVE-2026-55595.html
* https://www.suse.com/security/cve/CVE-2026-55597.html
* https://www.suse.com/security/cve/CVE-2026-56361.html
* https://www.suse.com/security/cve/CVE-2026-56363.html
* https://www.suse.com/security/cve/CVE-2026-56364.html
* https://www.suse.com/security/cve/CVE-2026-56374.html
* https://www.suse.com/security/cve/CVE-2026-56379.html