Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: - https://bugs.mageia.org/show_bug.cgi?id=34163 . MGASA-2025-0132 - Updated graphicsmagick packages fix security vulnerabilities Publication date: 12 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0132.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-27795 ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795) References: - https://bugs.mageia.org/show_bug.cgi?id=34163 - https://lwn.net/Articles/1016352/ - https://www.cve.org/CVERecord?id=CVE-2025-27795 SRPMS: - 9/core/graphicsmagick-1.3.40-1.1.mga9 - 9/tainted/graphicsmagick-1.3.40-1.1.mga9.tainted . Mageia 9 enhances GraphicsMagick to resolve significant image dimension issues. This update addresses vulnerabilities identified as CVE-2025-27795.. Mageia 2025, graphicsmagick security, image resource limits, software update, security patch. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for GraphicsMagick Announcement ID: SUSE-SU-2025:1129-1 Release Date: 2025-04-03T11:54:25Z Rating: moderate References: * bsc#1239044 Cross-References: * CVE-2025-27795 CVSS scores: * CVE-2025-27795 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-27795 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L * CVE-2025-27795 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issues: * CVE-2025-27795: Fixed missing image dimension resource limits in JXL (bsc#1239044) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1129=1 openSUSE-SLE-15.6-2025-1129=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1129=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * GraphicsMagick-devel-1.3.42-150600.3.4.1 * GraphicsMagick-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick++-devel-1.3.42-150600.3.4.1 *GraphicsMagick-debugsource-1.3.42-150600.3.4.1 * libGraphicsMagick3-config-1.3.42-150600.3.4.1 * perl-GraphicsMagick-1.3.42-150600.3.4.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-devel-1.3.42-150600.3.4.1 * GraphicsMagick-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick++-devel-1.3.42-150600.3.4.1 * GraphicsMagick-debugsource-1.3.42-150600.3.4.1 * libGraphicsMagick3-config-1.3.42-150600.3.4.1 * perl-GraphicsMagick-1.3.42-150600.3.4.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27795.html * https://bugzilla.suse.com/show_bug.cgi?id=1239044 . A security patch for GraphicsMagick addresses inadequate resource constraints on image dimensions, classified with moderate urgency.. GraphicsMagick update, openSUSE advisory, moderate threat, resource limits fix. . LinuxSecurity.com Team
* bsc#1239044 Cross-References: * CVE-2025-27795 . # Security update for GraphicsMagick Announcement ID: SUSE-SU-2025:1129-1 Release Date: 2025-04-03T11:54:25Z Rating: moderate References: * bsc#1239044 Cross-References: * CVE-2025-27795 CVSS scores: * CVE-2025-27795 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-27795 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L * CVE-2025-27795 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issues: * CVE-2025-27795: Fixed missing image dimension resource limits in JXL (bsc#1239044) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1129=1 openSUSE-SLE-15.6-2025-1129=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1129=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * GraphicsMagick-devel-1.3.42-150600.3.4.1 * GraphicsMagick-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick++-devel-1.3.42-150600.3.4.1 *GraphicsMagick-debugsource-1.3.42-150600.3.4.1 * libGraphicsMagick3-config-1.3.42-150600.3.4.1 * perl-GraphicsMagick-1.3.42-150600.3.4.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-devel-1.3.42-150600.3.4.1 * GraphicsMagick-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.4.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.4.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.4.1 * libGraphicsMagick++-devel-1.3.42-150600.3.4.1 * GraphicsMagick-debugsource-1.3.42-150600.3.4.1 * libGraphicsMagick3-config-1.3.42-150600.3.4.1 * perl-GraphicsMagick-1.3.42-150600.3.4.1 * GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27795.html * https://bugzilla.suse.com/show_bug.cgi?id=1239044 . SUSE's latest patch for ImageMagick resolves a significant vulnerability, enhancing resource management related to CVE-2025-28912.. GraphicsMagick update, SUSE Linux security, resource limit fix, software patching. . LinuxSecurity.com Team
New dnsmasq packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] dnsmasq (SSA:2024-044-02) New dnsmasq packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/dnsmasq-2.90-i586-1_slack15.0.txz: Upgraded. Add limits on the resources used to do DNSSEC validation. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-50387 https://www.cve.org/CVERecord?id=CVE-2023-50868 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/dnsmasq-2.90-i586-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/dnsmasq-2.90-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/dnsmasq-2.90-i586-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/dnsmasq-2.90-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 5c3dee26922dd2a3f58d1e5c70f9f284 dnsmasq-2.90-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 35f4d14b31baf2de9e3910f0f052f25d dnsmasq-2.90-x86_64-1_slack15.0.txz Slackware -current package: 1210b07b47998ab00dcf6cc7e3c9dd30 n/dnsmasq-2.90-i586-1.txz Slackware x86_64 -current package: 9862a73b6a5462656da236cd0ec4f9c2 n/dnsmasq-2.90-x86_64-1.txz Installation instructions: +------------------------+ Upgrade thepackage as root: # upgradepkg dnsmasq-2.90-i586-1_slack15.0.txz Then restart dnsmasq if you are using it: # sh /etc/rc.d/rc.dnsmasq restart +-----+ . Critical dnsmasq packages for Slackware 15.0 resolve significant issues and enforce resource limits on DNSSEC validation.. Dnsmasq, Slackware, Security Updates, Package Upgrade, DNSSEC. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.