This update for ImageMagick fixes the following issues
This update for ImageMagick fixes the following issues
* CVE-2026-33899: Denial of Service via out-of-bounds write in XML parsing
(bsc#1262154).
* CVE-2026-33900: Denial of Service via integer truncation in viff encoder
(bsc#1262156).
* CVE-2026-33901: Denial of Service due to heap buffer overflow in MVG decoder
(bsc#1262155).
* CVE-2026-33908: Denial of Service via deeply nested XML file processing
(bsc#1262152).
* CVE-2026-34238: Denial of Service via integer overflow in despeckle
operation (bsc#1262147).
* CVE-2026-40169: Denial of Service via crafted image leading to out-of-bounds
write (bsc#1262150).
* CVE-2026-40310: Denial of service via heap out-of-bounds write in JP2
encoder (bsc#1262148).
* CVE-2026-40311: Denial of Service via heap use-after-free in XMP profile
processing (bsc#1262146).
* CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048).
*...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2580=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2580=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2580=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2580=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2580=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-2580=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2580=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t...
Read the Full Advisory* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.87.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.87.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.87.1
* ImageMagick-7.1.0.9-150400.6.87.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.87.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.87.1
* perl-PerlMagick-7.1.0.9-150400.6.87.1
* ImageMagick-devel-7.1.0.9-150400.6.87.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.87.1
* libMagick++-devel-7.1.0.9-150400.6.87.1
* ImageMagick-debugsource-7.1.0.9-150400.6.87.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.87.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.87.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.87.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.87.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.87.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.87.1
*...
Read the Full Advisory* bsc#1262146
* bsc#1262147
* bsc#1262148
* bsc#1262150
* bsc#1262152
* bsc#1262154
* bsc#1262155
* bsc#1262156
* bsc#1265048
* bsc#1268092
* bsc#1268094
* bsc#1268095
* bsc#1268096
* bsc#1268101
* bsc#1268103
* bsc#1268105
* bsc#1268108
* bsc#1268110
* bsc#1268111
* bsc#1268112
* bsc#1268113
* bsc#1268114
* bsc#1268117
* bsc#1268120
* bsc#1268121
* bsc#1268122
* bsc#1268124
* bsc#1268125
* bsc#1268126
## References:
* https://www.suse.com/security/cve/CVE-2026-33899.html
* https://www.suse.com/security/cve/CVE-2026-33900.html
* https://www.suse.com/security/cve/CVE-2026-33901.html
* https://www.suse.com/security/cve/CVE-2026-33908.html
* https://www.suse.com/security/cve/CVE-2026-34238.html
* https://www.suse.com/security/cve/CVE-2026-40169.html
* https://www.suse.com/security/cve/CVE-2026-40310.html
* https://www.suse.com/security/cve/CVE-2026-40311.html
* https://www.suse.com/security/cve/CVE-2026-42050.html
* https://www.suse.com/security/cve/CVE-2026-42326.html
* https://www.suse.com/security/cve/CVE-2026-45031.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.