{"id":"SUSE-SU-2026:3193-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues\n\n- CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081).\n- CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in\n  `OpenPixelCache` (bsc#1271100).\n- CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316).\n- CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314).\n- CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315).\n- CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495).\n- CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).\n- CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496).\n- CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313).\n- CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312).\n- CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311).\n- CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497).\n- CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294).\n- CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493).\n- CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492).\n- CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491).\n- CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490).\n- CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489).\n- CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488).\n- CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487).\n- CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486).\n- CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293).\n- CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-geometry` is specified (bsc#1271484).\n","modified":"2026-07-23T09:45:06.800657987Z","published":"2026-07-22T14:27:14Z","related":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56372","CVE-2026-56373","CVE-2026-56375","CVE-2026-56377","CVE-2026-61464","CVE-2026-61465","CVE-2026-61857","CVE-2026-61858","CVE-2026-61859","CVE-2026-61861","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61870","CVE-2026-61872"],"upstream":["CVE-2026-55628","CVE-2026-56362","CVE-2026-56366","CVE-2026-56372","CVE-2026-56373","CVE-2026-56375","CVE-2026-56377","CVE-2026-61464","CVE-2026-61465","CVE-2026-61857","CVE-2026-61858","CVE-2026-61859","CVE-2026-61861","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61870","CVE-2026-61872"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263193-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268640"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270081"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271312"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271315"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271316"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271487"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271488"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271491"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271497"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56372"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61866"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61872"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.0.9-150400.6.101.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-config-7-upstream":"7.1.0.9-150400.6.101.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3193-1.json"}}],"schema_version":"1.7.5"}