## This update for ImageMagick fixes the following issues: * CVE-2026-22770: improper pointer initialization can cause denial of service (bsc#1256969). * CVE-2026-23874: manipulation of digital images can lead to stack overflow (bsc#1256976). * CVE-2026-23876: maliciously crafted image can lead to heap buffer overflow (bsc#1256962). * CVE-2026-23952: processing comment tag can cause null pointer dereference (bsc#1257076). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-437=1 * Development Tools Module 15-SP7
* bsc#1256962
* bsc#1256969
* bsc#1256976
* bsc#1257076
Cross-
* CVE-2026-22770
* CVE-2026-23874
* CVE-2026-23876
* CVE-2026-23952
CVSS scores:
* CVE-2026-22770 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-22770 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-22770 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-22770 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-23874 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23874 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-23874 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-23876 ( SUSE ): 9.2
Get the latest Linux and open source security news straight to your inbox.