Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for ImageMagick fixes the following issues
* CVE-2026-55628: policy bypass in concatenate operation due to missing checks
(bsc#1270081).
* CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to
metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).
* CVE-2026-56366: META reader memory leak in the APP1JPEG input path
(bsc#1271316).
* CVE-2026-56372: heap buffer overflow read in magnify operation via
unrecognized `magnify:method` value (bsc#1271314).
* CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640
bsc#1271315).
* CVE-2026-56375: possible memory leak in ASHLAR coder when action fails
(bsc#1271495).
* CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).
* CVE-2026-61464: heap buffer overwrite in X11 import with crafted window
title (bsc#1271496).
* CVE-2026-61465: policy bypass possible with matrix-backed operations
(bsc#1271313).
* CVE-2026-61857:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3193=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3193=1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ImageMagick-debugsource-7.1.0.9-150400.6.101.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.101.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.101.1
* ImageMagick-extra-7.1.0.9-150400.6.101.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.101.1
* ImageMagick-devel-7.1.0.9-150400.6.101.1
* libMagick++-devel-7.1.0.9-150400.6.101.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1
* ImageMagick-7.1.0.9-150400.6.101.1
* perl-PerlMagick-7.1.0.9-150400.6.101.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.101.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.101.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.101.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.101.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.101.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.101.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1
* openSUSE Leap 15.4 (x86_64)
* libMagick++-devel-32bit-7.1.0.9-150400.6.101.1
*...
Read the Full Advisory* bsc#1268640
* bsc#1270006
* bsc#1270081
* bsc#1271100
* bsc#1271293
* bsc#1271294
* bsc#1271311
* bsc#1271312
* bsc#1271313
* bsc#1271314
* bsc#1271315
* bsc#1271316
* bsc#1271484
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271495
* bsc#1271496
* bsc#1271497
## References:
* https://www.suse.com/security/cve/CVE-2026-55628.html
* https://www.suse.com/security/cve/CVE-2026-56362.html
* https://www.suse.com/security/cve/CVE-2026-56366.html
* https://www.suse.com/security/cve/CVE-2026-56372.html
* https://www.suse.com/security/cve/CVE-2026-56373.html
* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-56377.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61465.html
* https://www.suse.com/security/cve/CVE-2026-61857.html
* https://www.suse.com/security/cve/CVE-2026-61858.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.