Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

ImageMagick update fixes multiple security risks

SUSE-SU-2026:0853-1
Summary

ImageMagick has released a security update to fix multiple issues that could allow hackers to crash the software, steal sensitive information, or take control of your computer. These vulnerabilities affect how ImageMagick processes certain image file types. To stay secure, update your ImageMagick installation to the latest version.

What to do
  • Update imagemagick to version 7.1.0.9-150400.6.68.2.
Affected software
VendorProductAffected versionsFix available
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
imagemagick <= 7.1.0.9-150400.6.68.2 7.1.0.9-150400.6.68.2
Original title
Security update for ImageMagick
Original description
This update for ImageMagick fixes the following issues:

- CVE-2026-24481: Possible Heap Information Disclosure in PSD ZIP Decompression (bsc#1258743).
- CVE-2026-24484: denial of service vulnerability via multi-layer nested MVG to SVG conversion (bsc#1258790).
- CVE-2026-24485: denial of service via malformed PCD file processing (bsc#1258791).
- CVE-2026-25576: Out of bounds read in multiple coders that read raw pixel data (bsc#1258748).
- CVE-2026-25637: Denial of Service via crafted image due to memory leak (bsc#1258759).
- CVE-2026-25638: Denial of Service due to memory leak in image processing (bsc#1258793).
- CVE-2026-25795: Denial of Service due to NULL pointer dereference during temporary file creation failure
(bsc#1258792).
- CVE-2026-25796: Memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths
(bsc#1258757).
- CVE-2026-25797: Code injection in various encoders (bsc#1258770).
- CVE-2026-25798: NULL Pointer Dereference in ClonePixelCacheRepository via crafted image (bsc#1258787).
- CVE-2026-25799: Division-by-Zero in YUV sampling factor validation leads to crash (bsc#1258786).
- CVE-2026-25897: Out-of-bounds heap write via integer overflow in sun decoder (bsc#1258799).
- CVE-2026-25898: Information disclosure or denial of service via crafted image with invalid pixel index (bsc#1258807).
- CVE-2026-25965: Policy bypass through path traversal allows reading restricted content despite secured policy
(bsc#1258785).
- CVE-2026-25966: Security Policy Bypass through config/policy-secure.xml via 'fd handler' leads to stdin/stdout access
(bsc#1258780).
- CVE-2026-25970: Memory corruption and denial of service via signed integer overflow in SIXEL decoder (bsc#1258802).
- CVE-2026-25971: MSL: Stack overflow in ProcessMSLScript (bsc#1258774).
- CVE-2026-25983: Denial of service via crafted MSL script (bsc#1258805).
- CVE-2026-25986: Denial of Service via malicious YUV image processing (bsc#1258818).
- CVE-2026-25987: Memory disclosure and denial of service via crafted MAP files (bsc#1258821).
- CVE-2026-25988: Denial of Service due to memory leak in image processing (bsc#1258810).
- CVE-2026-25989: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG
decoder (bsc#1258771).
- CVE-2026-26066: Infinite loop when writing IPTCTEXT leads to denial of service via crafted profile (bsc#1258769).
- CVE-2026-26284: Heap overflow in pcd decoder leads to out of bounds read (bsc#1258765).
- CVE-2026-26983: Invalid MSL <map> can result in a use after free (bsc#1258763).
- CVE-2026-27798: Heap Buffer Over-read in WaveletDenoise when processing small images (bsc#1259018).
- CVE-2026-27799: ImageMagick has a heap Buffer Over-read in its DJVU image format handler (bsc#1259017).
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026