Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

openSUSE ImageMagick Important Memory Leak Policy Bypass Vuln 2026-21426-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
ImageMagick update for openSUSE addresses important issues. Install the latest patch to fix vulnerabilities and bugs.
openSUSE released an important security update for ImageMagick addressing 15 vulnerabilities, including memory leaks and command injection issues, affecting openSUSE Leap 16.0.

Description

This update for ImageMagick fixes the following issues

- CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).

- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).

- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).

- CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).

- CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).

- CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).

- CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).

- CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).

- CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).

- CVE-2026-61866: Memory Leak in JNG encoder...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

ImageMagick-7.1.2.0-160000.13.1

ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1

ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1

ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1

ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1

ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1

ImageMagick-devel-7.1.2.0-160000.13.1

ImageMagick-doc-7.1.2.0-160000.13.1

ImageMagick-extra-7.1.2.0-160000.13.1

libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1

libMagick++-devel-7.1.2.0-160000.13.1

libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1

libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1

perl-PerlMagick-7.1.2.0-160000.13.1

References

* bsc#1268878

* bsc#1271484

* bsc#1271485

* bsc#1271486

* bsc#1271487

* bsc#1271488

* bsc#1271489

* bsc#1271490

* bsc#1271491

* bsc#1271492

* bsc#1271493

* bsc#1271494

* bsc#1271495

* bsc#1271496

* bsc#1271497

References:

* https://www.suse.com/security/cve/CVE-2026-56375.html

* https://www.suse.com/security/cve/CVE-2026-56379.html

* https://www.suse.com/security/cve/CVE-2026-61464.html

* https://www.suse.com/security/cve/CVE-2026-61859.html

* https://www.suse.com/security/cve/CVE-2026-61860.html

* https://www.suse.com/security/cve/CVE-2026-61862.html

* https://www.suse.com/security/cve/CVE-2026-61863.html

* https://www.suse.com/security/cve/CVE-2026-61864.html

* https://www.suse.com/security/cve/CVE-2026-61865.html

* https://www.suse.com/security/cve/CVE-2026-61866.html

* https://www.suse.com/security/cve/CVE-2026-61867.html

* https://www.suse.com/security/cve/CVE-2026-61868.html

* https://www.suse.com/security/cve/CVE-2026-61869.html

* https://www.suse.com/security/cve/CVE-2026-61871.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21426-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.