Skip to content
SUSE ImageMagick Moderate Buffer Overwrite and Memory Leak Fix 2026-23312

SUSE ImageMagick Moderate Buffer Overwrite and Memory Leak Fix 2026-23312

Linuxsecurity LinuxSecurity Advisories August 31, 2026

Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×

## This update for ImageMagick fixes the following issues: * CVE-2026-56365: memory leak in the PNG encoder when writing MNG images (bsc#1270004). * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder leading to heap buffer overwrite when extremely large files are processed on 32-bit builds (bsc#1272580). * CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). * CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of- file check (bsc#1272953). * Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

## This update for ImageMagick fixes the following issues: * CVE-2026-56365: memory leak in the PNG encoder when writing MNG images (bsc#1270004). * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder leading to heap buffer overwrite when extremely large files are processed on 32-bit builds (bsc#1272580). * CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). * CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of- file check (bsc#1272953). * Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

* CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

* CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

* CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

* CVE-2026-56365 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-56365 ( NVD ): 6.3

Announcement ID: SUSE-SU-2026:23312-1 Release Date: 2026-08-24T18:56:27Z Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases