Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 546
Alerts This Week
Warning Icon 1 546

SUSE ImageMagick Important Heap Overflow Issues Advisory 2026-22620-1

suse
Calendar Grey July 16, 2026
Scroller Suse
Update for ImageMagick solves 10 issues including heap overflows and memory leaks. Immediate installation recommended.
A security update for ImageMagick addresses multiple vulnerabilities, including buffer overflows, memory leaks, and potential for arbitrary command injection, with recommended inst...

Summary

## This update for ImageMagick fixes the following issues * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001).

References

* bsc#1268640

* bsc#1268878

* bsc#1270001

* bsc#1270002

* bsc#1270003

* bsc#1270073

* bsc#1270074

* bsc#1270077

* bsc#1270079

* bsc#1270080

* bsc#1271099

Cross-

* CVE-2026-53466

* CVE-2026-53467

* CVE-2026-55594

* CVE-2026-55595

* CVE-2026-55597

* CVE-2026-56361

* CVE-2026-56363

* CVE-2026-56364

* CVE-2026-56374

* CVE-2026-56379

CVSS scores:

* CVE-2026-53466 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

* CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

* CVE-2026-53467 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22620-1
Release Date: 2026-07-10T08:56:16Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.