Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 468
Alerts This Week
Warning Icon 1 468

openSUSE ImageMagick Important Security Fix for Multiple Flaws 2026-3219-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
Discover critical fixes for ImageMagick addressing multiple security flaws in openSUSE. Update now for safety.
SUSE has released an important security update for ImageMagick, addressing 25 vulnerabilities and providing a fix for significant bugs affecting openSUSE Leap and SUSE Linux Enterp...

Description

This update for ImageMagick fixes the following issues:

* CVE-2026-55628: policy bypass in concatenate operation due to missing checks

(bsc#1270081).

* CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to

metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).

* CVE-2026-56366: META reader memory leak in the APP1JPEG input path

(bsc#1271316).

* CVE-2026-56372: heap buffer overflow read in magnify operation via

unrecognized `magnify:method` value (bsc#1271314).

* CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640,

bsc#1271315).

* CVE-2026-56375: possible memory leak in ASHLAR coder when action fails

(bsc#1271495).

* CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).

* CVE-2026-61464: heap buffer overwrite in X11 import with crafted window

title (bsc#1271496).

* CVE-2026-61465: policy bypass possible with matrix-backed operations

(bsc#1271313).

* CVE-2026-61857:...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3219=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3219=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3219=1

Package List

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* libMagick++-devel-7.1.1.21-150600.3.80.2

* perl-PerlMagick-7.1.1.21-150600.3.80.2

* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2

* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2

* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2

* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2

* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2

* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2

* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2

* ImageMagick-7.1.1.21-150600.3.80.2

* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2

* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2

* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2

* ImageMagick-debugsource-7.1.1.21-150600.3.80.2

* ImageMagick-devel-7.1.1.21-150600.3.80.2

* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2

* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2

* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2

*...

Read the Full Advisory

References

* bsc#1268640

* bsc#1268878

* bsc#1270006

* bsc#1270081

* bsc#1271100

* bsc#1271293

* bsc#1271294

* bsc#1271311

* bsc#1271312

* bsc#1271313

* bsc#1271314

* bsc#1271315

* bsc#1271316

* bsc#1271484

* bsc#1271486

* bsc#1271487

* bsc#1271488

* bsc#1271489

* bsc#1271490

* bsc#1271491

* bsc#1271492

* bsc#1271493

* bsc#1271494

* bsc#1271495

* bsc#1271496

* bsc#1271497

## References:

* https://www.suse.com/security/cve/CVE-2026-55628.html

* https://www.suse.com/security/cve/CVE-2026-56362.html

* https://www.suse.com/security/cve/CVE-2026-56366.html

* https://www.suse.com/security/cve/CVE-2026-56372.html

* https://www.suse.com/security/cve/CVE-2026-56373.html

* https://www.suse.com/security/cve/CVE-2026-56375.html

* https://www.suse.com/security/cve/CVE-2026-56377.html

* https://www.suse.com/security/cve/CVE-2026-56379.html

* https://www.suse.com/security/cve/CVE-2026-61464.html

* https://www.suse.com/security/cve/CVE-2026-61465.html

* https://www.suse.com/security/cve/CVE-2026-61857.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3219-1
Release Date: 2026-07-23T17:35:28Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.