Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 427
Alerts This Week
Warning Icon 1 427

SUSE ImageMagick Important Heap Buffer Overflow Fix SUSE-2026-3219-1

suse
Calendar Grey July 24, 2026
Scroller Suse
This update for ImageMagick resolves critical issues with 25 vulnerabilities. Installation can enhance system security and stability.
A security update for ImageMagick addresses 25 vulnerabilities, including heap buffer overflows and memory leaks, providing critical patches for affected SUSE products and openSUSE...

Summary

## This update for ImageMagick fixes the following issues: * CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). * CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). * CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). * CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). * CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640, bsc#1271315). * CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). * CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).

References

* bsc#1268640

* bsc#1268878

* bsc#1270006

* bsc#1270081

* bsc#1271100

* bsc#1271293

* bsc#1271294

* bsc#1271311

* bsc#1271312

* bsc#1271313

* bsc#1271314

* bsc#1271315

* bsc#1271316

* bsc#1271484

* bsc#1271486

* bsc#1271487

* bsc#1271488

* bsc#1271489

* bsc#1271490

* bsc#1271491

* bsc#1271492

* bsc#1271493

* bsc#1271494

* bsc#1271495

* bsc#1271496

* bsc#1271497

Cross-

* CVE-2026-55628

* CVE-2026-56362

* CVE-2026-56366

* CVE-2026-56372

* CVE-2026-56373

* CVE-2026-56375

* CVE-2026-56377

* CVE-2026-56379

* CVE-2026-61464

* CVE-2026-61465

* CVE-2026-61857

* CVE-2026-61858

* CVE-2026-61859

* CVE-2026-61860

* CVE-2026-61861

* CVE-2026-61862

* CVE-2026-61863

* CVE-2026-61864

* CVE-2026-61865

* CVE-2026-61866

* CVE-2026-61867

* CVE-2026-61868

* CVE-2026-61869

* CVE-2026-61870

* CVE-2026-61872

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3219-1
Release Date: 2026-07-23T17:35:28Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.