openSUSE-SU-2026:21291-1: important: Security update for ImageMagick

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for imagemagick
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21291-1
Rating: important
References:

  * bsc#1268640
  * bsc#1268878
  * bsc#1270001
  * bsc#1270002
  * bsc#1270003
  * bsc#1270073
  * bsc#1270074
  * bsc#1270077
  * bsc#1270079
  * bsc#1270080
  * bsc#1271099



Cross-References:

  * CVE-2026-53466
  * CVE-2026-53467
  * CVE-2026-55594
  * CVE-2026-55595
  * CVE-2026-55597
  * CVE-2026-56361
  * CVE-2026-56363
  * CVE-2026-56364
  * CVE-2026-56374
  * CVE-2026-56379



CVSS scores:

  * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
  * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
  * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 10 vulnerabilities and has 11 bug fixes can now be installed.

Description:

This update for ImageMagick fixes the following issues

- CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read
  (bsc#1270073).
- CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure
  (bsc#1270074).
- CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is
  provided (bsc#1270077).
- CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop
  (bsc#1270079).
- CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080).
- CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001).
- CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application
  crash (bsc#1270002).
- CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML
  files
  with unclosed device elements (bsc#1270003).
- CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing
  `ftxt:format` (bsc#1271099).
- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG
  files (bsc#1268878).
- GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640).


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1202=1

Package List:

- openSUSE Leap 16.0:

  ImageMagick-7.1.2.0-160000.11.1
  ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1
  ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1
  ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1
  ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1
  ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1
  ImageMagick-devel-7.1.2.0-160000.11.1
  ImageMagick-doc-7.1.2.0-160000.11.1
  ImageMagick-extra-7.1.2.0-160000.11.1
  libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1
  libMagick++-devel-7.1.2.0-160000.11.1
  libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1
  libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1
  perl-PerlMagick-7.1.2.0-160000.11.1

References:

  * https://www.suse.com/security/cve/CVE-2026-53466.html
  * https://www.suse.com/security/cve/CVE-2026-53467.html
  * https://www.suse.com/security/cve/CVE-2026-55594.html
  * https://www.suse.com/security/cve/CVE-2026-55595.html
  * https://www.suse.com/security/cve/CVE-2026-55597.html
  * https://www.suse.com/security/cve/CVE-2026-56361.html
  * https://www.suse.com/security/cve/CVE-2026-56363.html
  * https://www.suse.com/security/cve/CVE-2026-56364.html
  * https://www.suse.com/security/cve/CVE-2026-56374.html
  * https://www.suse.com/security/cve/CVE-2026-56379.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.