{"id":"SUSE-SU-2026:22861-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues\n\n- CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).\n- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).\n- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).\n- CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).\n- CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).\n- CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).\n- CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).\n- CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).\n- CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).\n- CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489).\n- CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488).\n- CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487).\n- CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486).\n- CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485).\n- CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484).\n","modified":"2026-07-28T20:42:29.888429393Z","published":"2026-07-22T18:59:41Z","related":["CVE-2026-56375","CVE-2026-56379","CVE-2026-61464","CVE-2026-61859","CVE-2026-61860","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61871","CVE-2026-61872"],"upstream":["CVE-2026-56375","CVE-2026-56379","CVE-2026-61464","CVE-2026-61859","CVE-2026-61860","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61871","CVE-2026-61872"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622861-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271487"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271488"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271491"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271497"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61866"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61872"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.13.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.13.1","ImageMagick":"7.1.2.0-160000.13.1","ImageMagick-extra":"7.1.2.0-160000.13.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.13.1","libMagick++-devel":"7.1.2.0-160000.13.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-open":"7.1.2.0-160000.13.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.13.1","ImageMagick-devel":"7.1.2.0-160000.13.1","ImageMagick-doc":"7.1.2.0-160000.13.1","perl-PerlMagick":"7.1.2.0-160000.13.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22861-1.json"}},{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.13.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-extra":"7.1.2.0-160000.13.1","libMagick++-devel":"7.1.2.0-160000.13.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.13.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.13.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.13.1","perl-PerlMagick":"7.1.2.0-160000.13.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.13.1","ImageMagick":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-open":"7.1.2.0-160000.13.1","ImageMagick-devel":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.13.1","ImageMagick-doc":"7.1.2.0-160000.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22861-1.json"}}],"schema_version":"1.7.5"}