Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for ImageMagick fixes the following issues: * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640, bsc#1271315). * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).
* bsc#1268640
* bsc#1268878
* bsc#1270006
* bsc#1270081
* bsc#1271100
* bsc#1271293
* bsc#1271294
* bsc#1271311
* bsc#1271312
* bsc#1271313
* bsc#1271314
* bsc#1271315
* bsc#1271316
* bsc#1271484
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271494
* bsc#1271495
* bsc#1271496
* bsc#1271497
Cross-
* CVE-2026-55628
* CVE-2026-56362
* CVE-2026-56366
* CVE-2026-56372
* CVE-2026-56373
* CVE-2026-56375
* CVE-2026-56377
* CVE-2026-56379
* CVE-2026-61464
* CVE-2026-61465
* CVE-2026-61857
* CVE-2026-61858
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61861
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61870
* CVE-2026-61872
Get the latest Linux and open source security news straight to your inbox.