Back Linuxsecurity openSUSE ImageMagick Important Denial of Service Updates 2026-21071
- CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092).
- CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094).
- CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta
encoder (bsc#1268102).
- CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095).
- CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096).
- CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101).
- CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112).
- CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder
- openSUSE Leap 16.0:
ImageMagick-7.1.2.0-160000.10.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.10.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.10.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.10.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.10.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.10.1
ImageMagick-devel-7.1.2.0-160000.10.1
ImageMagick-doc-7.1.2.0-160000.10.1
ImageMagick-extra-7.1.2.0-160000.10.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.10.1
libMagick++-devel-7.1.2.0-160000.10.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.10.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.10.1
perl-PerlMagick-7.1.2.0-160000.10.1
*
*
*
*
*
*
*
*
*
*
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
