{"id":"SUSE-SU-2026:22829-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues\n\n- CVE-2026-55628: Policy Bypass in concatenate operation due to missing checks (bsc#1270081).\n- CVE-2026-56362: Heap-buffer-overflow read in GetPixelIndex due to metadata-cache desynchronization in OpenPixelCache (bsc#1271100).\n- CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316).\n- CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized magnify:method value (bsc#1271314).\n- CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315).\n- CVE-2026-56377: Policy Bypass can create or truncate files (bsc#1270006).\n- CVE-2026-61465: Policy Bypass possible with matrix-backed operations (bsc#1271313).\n- CVE-2026-61857: Heap-use-after-free via XMP profile could result in a crash (bsc#1271312).\n- CVE-2026-61858: Policy Bypass in APNG encoder and delegates due to a missing check (bsc#1271311).\n- CVE-2026-61861: Use-After-Free in FormatMagickCaption when memory allocation fails (bsc#1271294).\n- CVE-2026-61870: Memory leak in VIFF encoder when allocation fails (bsc#1271293).\n","modified":"2026-07-28T20:42:27.204162427Z","published":"2026-07-20T10:18:51Z","related":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56372","CVE-2026-56373","CVE-2026-56377","CVE-2026-61465","CVE-2026-61857","CVE-2026-61858","CVE-2026-61861","CVE-2026-61870"],"upstream":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56372","CVE-2026-56373","CVE-2026-56377","CVE-2026-61465","CVE-2026-61857","CVE-2026-61858","CVE-2026-61861","CVE-2026-61870"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622829-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268640"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61870"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.12.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-extra":"7.1.2.0-160000.12.1","libMagick++-devel":"7.1.2.0-160000.12.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.12.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.12.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.12.1","perl-PerlMagick":"7.1.2.0-160000.12.1","ImageMagick-doc":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.12.1","ImageMagick-devel":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-open":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.12.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.12.1","ImageMagick":"7.1.2.0-160000.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22829-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.12.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-config-7-upstream-open":"7.1.2.0-160000.12.1","ImageMagick-devel":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.12.1","libMagick++-devel":"7.1.2.0-160000.12.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.12.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.12.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.12.1","ImageMagick-extra":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.12.1","perl-PerlMagick":"7.1.2.0-160000.12.1","ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.12.1","ImageMagick-doc":"7.1.2.0-160000.12.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.12.1","ImageMagick":"7.1.2.0-160000.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22829-1.json"}}],"schema_version":"1.7.5"}