Skip to content
SUSE ImageMagick Important Buffer Overflow and Memory Leak Fix 2026-4376

SUSE ImageMagick Important Buffer Overflow and Memory Leak Fix 2026-4376

Linuxsecurity •LinuxSecurity Advisories • September 29, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

## This update for ImageMagick fixes the following issues: * CVE-2026-62343: heap buffer over-write in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer over-write in fx operation (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder causes heap buffer over- write when processing extremly large files on 32-bit builds (bsc#1272580). * CVE-2026-64685: heap buffer over-read in BGR decoder due to missing end-of- file check (bsc#1272953). * CVE-2026-66011: memory Leak when providing invalid options to the cli (bsc#1272577). * CVE-2026-86420: denial of Service due to memory budget exhaustion (bsc#1279696). * CVE-2026-86421: denial of Service via memory leak in MSL decoder (bsc#1279711).

## This update for ImageMagick fixes the following issues: * CVE-2026-62343: heap buffer over-write in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer over-write in fx operation (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder causes heap buffer over- write when processing extremly large files on 32-bit builds (bsc#1272580). * CVE-2026-64685: heap buffer over-read in BGR decoder due to missing end-of- file check (bsc#1272953). * CVE-2026-66011: memory Leak when providing invalid options to the cli (bsc#1272577). * CVE-2026-86420: denial of Service due to memory budget exhaustion (bsc#1279696). * CVE-2026-86421: denial of Service via memory leak in MSL decoder (bsc#1279711).

* CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

* CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

* CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

* CVE-2026-62343 ( SUSE ): 5.6

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Announcement ID: SUSE-SU-2026:4376-1 Release Date: 2026-09-28T15:16:15Z Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases