Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

SUSE ImageMagick Moderate Buffer Overflow Memory Leak Vuln 2026-3193-1

suse
Calendar Grey July 22, 2026
Scroller Suse
The SUSE security update for ImageMagick addresses 23 vulnerabilities with one critical fix, enhancing system safety.
A security update for ImageMagick resolves 23 vulnerabilities related to memory leaks, buffer overflows, and policy bypasses, requiring installation across several SUSE products.

Summary

## This update for ImageMagick fixes the following issues * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).

References

* bsc#1268640

* bsc#1270006

* bsc#1270081

* bsc#1271100

* bsc#1271293

* bsc#1271294

* bsc#1271311

* bsc#1271312

* bsc#1271313

* bsc#1271314

* bsc#1271315

* bsc#1271316

* bsc#1271484

* bsc#1271486

* bsc#1271487

* bsc#1271488

* bsc#1271489

* bsc#1271490

* bsc#1271491

* bsc#1271492

* bsc#1271493

* bsc#1271495

* bsc#1271496

* bsc#1271497

Cross-

* CVE-2026-55628

* CVE-2026-56362

* CVE-2026-56366

* CVE-2026-56372

* CVE-2026-56373

* CVE-2026-56375

* CVE-2026-56377

* CVE-2026-61464

* CVE-2026-61465

* CVE-2026-61857

* CVE-2026-61858

* CVE-2026-61859

* CVE-2026-61861

* CVE-2026-61862

* CVE-2026-61863

* CVE-2026-61864

* CVE-2026-61865

* CVE-2026-61866

* CVE-2026-61867

* CVE-2026-61868

* CVE-2026-61869

* CVE-2026-61870

* CVE-2026-61872

CVSS scores:

* CVE-2026-55628 ( SUSE ): 6.7

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3193-1
Release Date: 2026-07-22T14:27:15Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.