{"id":"openSUSE-SU-2026:21426-1","summary":"Security update for ImageMagick","details":"This update for ImageMagick fixes the following issues\n\n- CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).\n- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).\n- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).\n- CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).\n- CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).\n- CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).\n- CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).\n- CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).\n- CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).\n- CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489).\n- CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488).\n- CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487).\n- CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486).\n- CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485).\n- CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484).\n","modified":"2026-07-24T18:24:31.857104736Z","published":"2026-07-22T19:01:21Z","related":["CVE-2026-56375","CVE-2026-56379","CVE-2026-61464","CVE-2026-61859","CVE-2026-61860","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61871","CVE-2026-61872"],"upstream":["CVE-2026-56375","CVE-2026-56379","CVE-2026-61464","CVE-2026-61859","CVE-2026-61860","CVE-2026-61862","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-61866","CVE-2026-61867","CVE-2026-61868","CVE-2026-61869","CVE-2026-61871","CVE-2026-61872"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271487"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271488"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271489"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271491"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271496"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271497"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61865"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61866"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-61872"}],"affected":[{"package":{"name":"ImageMagick","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.2.0-160000.13.1"}]}],"ecosystem_specific":{"binaries":[{"ImageMagick":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-limited":"7.1.2.0-160000.13.1","ImageMagick-config-7-SUSE":"7.1.2.0-160000.13.1","ImageMagick-extra":"7.1.2.0-160000.13.1","libMagick++-7_Q16HDRI5":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-open":"7.1.2.0-160000.13.1","ImageMagick-doc":"7.1.2.0-160000.13.1","libMagick++-devel":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-secure":"7.1.2.0-160000.13.1","perl-PerlMagick":"7.1.2.0-160000.13.1","ImageMagick-config-7-upstream-websafe":"7.1.2.0-160000.13.1","libMagickCore-7_Q16HDRI10":"7.1.2.0-160000.13.1","libMagickWand-7_Q16HDRI10":"7.1.2.0-160000.13.1","ImageMagick-devel":"7.1.2.0-160000.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21426-1.json"}}],"schema_version":"1.7.5"}