{"id":"SUSE-SU-2026:3192-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues\n\n- CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081).\n- CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in\n  `OpenPixelCache` (bsc#1271100).\n- CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316).\n- CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315).\n- CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).\n- CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496).\n- CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312).\n- CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493).\n- CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492).\n- CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487).\n- CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486).\n- CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293).\n- CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-geometry` is specified (bsc#1271484).\n","modified":"2026-07-23T09:45:06.783284721Z","published":"2026-07-22T14:26:04Z","related":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56373","CVE-2026-56377","CVE-2026-61464","CVE-2026-61857","CVE-2026-61862","CVE-2026-61863","CVE-2026-61868","CVE-2026-61869","CVE-2026-61870","CVE-2026-61872"],"upstream":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56373","CVE-2026-56377","CVE-2026-61464","CVE-2026-61857","CVE-2026-61862","CVE-2026-61863","CVE-2026-61868","CVE-2026-61869","CVE-2026-61870","CVE-2026-61872"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263192-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268640"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271316"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271487"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61872"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.8.1-71.264.1"}]}],"ecosystem_specific":{"binaries":[{"libMagickWand-6_Q16-1":"6.8.8.1-71.264.1","ImageMagick-config-6-SUSE":"6.8.8.1-71.264.1","ImageMagick-config-6-upstream":"6.8.8.1-71.264.1","ImageMagick-devel":"6.8.8.1-71.264.1","libMagick++-devel":"6.8.8.1-71.264.1","libMagickCore-6_Q16-1":"6.8.8.1-71.264.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3192-1.json"}}],"schema_version":"1.7.5"}