{"id":"openSUSE-SU-2026:20606-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues:\n\n- CVE-2026-32259: stack out-of-bounds write due to a memory allocation failure in the sixel encoder can lead to a crash\n  (bsc#1259612).\n- CVE-2026-32636: out-of-bounds write of a single zero byte due to bug the `NewXMLTree` method can lead to denial of\n  service (bsc#1259872).\n- CVE-2026-33535: out-of-bounds write of a zero byte in X11 `display` interaction path can lead to a crash\n  (bsc#1260874).\n- CVE-2026-33536: stack out-of-bounds write due to incorrect return value on certain platforms can lead to a denial of\n  service (bsc#1260879).\n- CVE-2026-33899: out-of-bounds write of single zero byte in XML parsing can lead to a denial of service (bsc#1262154).\n- CVE-2026-33900: heap out-of-bounds write due to integer truncation in viff encoder can lead to a crash (bsc#1262156).\n- CVE-2026-33901: heap buffer overflow in the MVG decoder can lead to memory corruption or a crash (bsc#1262155).\n- CVE-2026-33902: stack buffer overflow in the FX expression parser can lead to a process crash (bsc#1262153).\n- CVE-2026-33905: out-of-bounds read in `-sample` operation can lead to a denial of service (bsc#1262097).\n- CVE-2026-33908: recursive execution with no depth limit imposed when processing XML files can lead to resource\n  exhaustion and a denial of service (bsc#1262152).\n- CVE-2026-34238: heap buffer overflow due to integer overflow in the despeckle operation can lead to a denial of\n  service (bsc#1262147).\n- CVE-2026-40169: out-of-bounds heap write when processing a crafted image and writing a YAML or JSON output can lead\n  to a crash (bsc#1262150).\n- CVE-2026-40183: heap out-of-bounds write in the JXL encoder can lead to a denial of service (bsc#1262145).\n- CVE-2026-40310: heap out-of-bounds write in the JP2 encoder can lead to a denial of service (bsc#1262148).\n- CVE-2026-40311: heap use-after-free when reading and printing values from an invalid XMP profile can lead to a denial\n  of service (bsc#1262146).\n- CVE-2026-40312: off-by-one error in the MSL decoder can lead to a crash (bsc#1262149).\n","modified":"2026-04-24T18:24:59.552984Z","published":"2026-04-22T11:02:58Z","related":["CVE-2026-32259","CVE-2026-32636","CVE-2026-33535","CVE-2026-33536","CVE-2026-33899","CVE-2026-33900","CVE-2026-33901","CVE-2026-33902","CVE-2026-33905","CVE-2026-33908","CVE-2026-34238","CVE-2026-40169","CVE-2026-40183","CVE-2026-40310","CVE-2026-40311","CVE-2026-40312"],"upstream":["CVE-2026-32259","CVE-2026-32636","CVE-2026-33535","CVE-2026-33536","CVE-2026-33899","CVE-2026-33900","CVE-2026-33901","CVE-2026-33902","CVE-2026-33905","CVE-2026-33908","CVE-2026-34238","CVE-2026-40169","CVE-2026-40183","CVE-2026-40310","CVE-2026-40311","CVE-2026-40312"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259872"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260874"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260879"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262146"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262147"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262148"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262149"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262152"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262154"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262155"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32259"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32636"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33535"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33536"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33900"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33905"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33908"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40169"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40183"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40312"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.8.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick-devel":"7.1.2.0-160000.8.1","ImageMagick-doc":"7.1.2.0-160000.8.1","ImageMagick-extra":"7.1.2.0-160000.8.1","libMagick++-devel":"7.1.2.0-160000.8.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.8.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.8.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.8.1","ImageMagick-config-7-upstream-open":"7.1.2.0-160000.8.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.8.1","ImageMagick":"7.1.2.0-160000.8.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.8.1","perl-PerlMagick":"7.1.2.0-160000.8.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.8.1","ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20606-1.json"}}],"schema_version":"1.7.5"}