Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

openSUSE ImageMagick Moderate Memory Leak Fix Advisory 2026-3193-1

opensuse
Calendar Grey July 22, 2026
Scroller Opensuse
This update for ImageMagick addresses 23 issues including memory leaks and buffer overflows on openSUSE.
SUSE released an ImageMagick update resolving 23 vulnerabilities, enhancing security through multiple fixes for memory leaks, buffer overflows, and policy bypasses across various a...

Description

This update for ImageMagick fixes the following issues

* CVE-2026-55628: policy bypass in concatenate operation due to missing checks

(bsc#1270081).

* CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to

metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).

* CVE-2026-56366: META reader memory leak in the APP1JPEG input path

(bsc#1271316).

* CVE-2026-56372: heap buffer overflow read in magnify operation via

unrecognized `magnify:method` value (bsc#1271314).

* CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640

bsc#1271315).

* CVE-2026-56375: possible memory leak in ASHLAR coder when action fails

(bsc#1271495).

* CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).

* CVE-2026-61464: heap buffer overwrite in X11 import with crafted window

title (bsc#1271496).

* CVE-2026-61465: policy bypass possible with matrix-backed operations

(bsc#1271313).

* CVE-2026-61857:...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* Desktop Applications Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3193=1

* openSUSE Leap 15.4

zypper in -t patch SUSE-2026-3193=1

Package List

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)

* ImageMagick-debugsource-7.1.0.9-150400.6.101.1

* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.101.1

* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.101.1

* ImageMagick-extra-7.1.0.9-150400.6.101.1

* ImageMagick-debuginfo-7.1.0.9-150400.6.101.1

* ImageMagick-devel-7.1.0.9-150400.6.101.1

* libMagick++-devel-7.1.0.9-150400.6.101.1

* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1

* ImageMagick-7.1.0.9-150400.6.101.1

* perl-PerlMagick-7.1.0.9-150400.6.101.1

* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.101.1

* ImageMagick-config-7-upstream-7.1.0.9-150400.6.101.1

* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.101.1

* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.101.1

* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.101.1

* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.101.1

* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.101.1

* openSUSE Leap 15.4 (x86_64)

* libMagick++-devel-32bit-7.1.0.9-150400.6.101.1

*...

Read the Full Advisory

References

* bsc#1268640

* bsc#1270006

* bsc#1270081

* bsc#1271100

* bsc#1271293

* bsc#1271294

* bsc#1271311

* bsc#1271312

* bsc#1271313

* bsc#1271314

* bsc#1271315

* bsc#1271316

* bsc#1271484

* bsc#1271486

* bsc#1271487

* bsc#1271488

* bsc#1271489

* bsc#1271490

* bsc#1271491

* bsc#1271492

* bsc#1271493

* bsc#1271495

* bsc#1271496

* bsc#1271497

## References:

* https://www.suse.com/security/cve/CVE-2026-55628.html

* https://www.suse.com/security/cve/CVE-2026-56362.html

* https://www.suse.com/security/cve/CVE-2026-56366.html

* https://www.suse.com/security/cve/CVE-2026-56372.html

* https://www.suse.com/security/cve/CVE-2026-56373.html

* https://www.suse.com/security/cve/CVE-2026-56375.html

* https://www.suse.com/security/cve/CVE-2026-56377.html

* https://www.suse.com/security/cve/CVE-2026-61464.html

* https://www.suse.com/security/cve/CVE-2026-61465.html

* https://www.suse.com/security/cve/CVE-2026-61857.html

* https://www.suse.com/security/cve/CVE-2026-61858.html

* https://www.suse.com/security/cve/CVE-2026-61859.html

*...

Read the Full Advisory

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3193-1
Release Date: 2026-07-22T14:27:15Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.