Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

SUSE ImageMagick Moderate Policy Bypass Memory Leak Vuln 2026-3192-1

suse
Calendar Grey July 22, 2026
Scroller Suse
ImageMagick update for SUSE addresses 13 vulnerabilities with one critical memory fix to ensure system integrity and safety.
A security update for ImageMagick resolves 13 vulnerabilities, including memory leaks and buffer overflows, applicable to SUSE Linux Enterprise Server 12 SP5 and related products.

Summary

## This update for ImageMagick fixes the following issues * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). * CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). * CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). * CVE-2026-61862: information disclosure when printing profiles with debug

References

* bsc#1268640

* bsc#1270006

* bsc#1270081

* bsc#1271100

* bsc#1271293

* bsc#1271312

* bsc#1271315

* bsc#1271316

* bsc#1271484

* bsc#1271486

* bsc#1271487

* bsc#1271492

* bsc#1271493

* bsc#1271496

Cross-

* CVE-2026-55628

* CVE-2026-56362

* CVE-2026-56366

* CVE-2026-56373

* CVE-2026-56377

* CVE-2026-61464

* CVE-2026-61857

* CVE-2026-61862

* CVE-2026-61863

* CVE-2026-61868

* CVE-2026-61869

* CVE-2026-61870

* CVE-2026-61872

CVSS scores:

* CVE-2026-55628 ( SUSE ): 6.7

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2026-56362 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3192-1
Release Date: 2026-07-22T14:26:04Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.