This update for ImageMagick fixes the following issues:
* CVE-2026-24484: denial of service via multi-layer nested MVG to SVG
conversion (bsc#1258790).
* CVE-2026-28493: integer overflow in the SIXEL decoder leads to out-of-bounds
write (bsc#1259446).
* CVE-2026-28494: missing bounds checks in the morphology kernel parsing
functions can lead to a stack buffer overflow (bsc#1259447).
* CVE-2026-28686: undersized output buffer allocation in the PCL encoder can
lead to a heap buffer overflow (bsc#1259448).
* CVE-2026-28687: heap use-after-free vulnerability in the MSL decoder via a
crafted MSL file (bsc#1259450).
* CVE-2026-28688: heap use-after-free in the MSL encoder when a cloned image
is destroyed twice (bsc#1259451).
* CVE-2026-28689: `domain="path"` authorization is checked before
final file open/use and allows for read/write bypass via symlink swaps
(bsc#1259452).
* CVE-2026-28690: missing bounds check in the MNG encoder...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-1497=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1497=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1497=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1497=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1497=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1497=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1497=1
* SUSE Linux Enterprise...
Read the Full Advisory* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.75.1
* ImageMagick-devel-7.1.0.9-150400.6.75.1
* ImageMagick-extra-7.1.0.9-150400.6.75.1
* ImageMagick-debugsource-7.1.0.9-150400.6.75.1
* ImageMagick-7.1.0.9-150400.6.75.1
* libMagick++-devel-7.1.0.9-150400.6.75.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.75.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.75.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.75.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.75.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.75.1
* perl-PerlMagick-7.1.0.9-150400.6.75.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.75.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.75.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.75.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.75.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.75.1
* openSUSE Leap 15.4 (x86_64)
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.75.1
*...
Read the Full Advisory* bsc#1258790
* bsc#1259446
* bsc#1259447
* bsc#1259448
* bsc#1259450
* bsc#1259451
* bsc#1259452
* bsc#1259455
* bsc#1259456
* bsc#1259457
* bsc#1259463
* bsc#1259464
* bsc#1259466
* bsc#1259467
* bsc#1259468
* bsc#1259528
* bsc#1259612
* bsc#1259872
* bsc#1260874
* bsc#1260879
* bsc#1262097
## References:
* https://www.suse.com/security/cve/CVE-2026-24484.html
* https://www.suse.com/security/cve/CVE-2026-28493.html
* https://www.suse.com/security/cve/CVE-2026-28494.html
* https://www.suse.com/security/cve/CVE-2026-28686.html
* https://www.suse.com/security/cve/CVE-2026-28687.html
* https://www.suse.com/security/cve/CVE-2026-28688.html
* https://www.suse.com/security/cve/CVE-2026-28689.html
* https://www.suse.com/security/cve/CVE-2026-28690.html
* https://www.suse.com/security/cve/CVE-2026-28691.html
* https://www.suse.com/security/cve/CVE-2026-28692.html
* https://www.suse.com/security/cve/CVE-2026-28693.html
* https://www.suse.com/security/cve/CVE-2026-30883.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.