Back Linuxsecurity SUSE ImageMagick Moderate Buffer Overwrite and Memory Leak Fix 2026-23312
Find practical guidance for preventing, investigating, and responding to Linux security problems. Review Linux Privileges ×
## This update for ImageMagick fixes the following issues: * CVE-2026-56365: memory leak in the PNG encoder when writing MNG images (bsc#1270004). * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder leading to heap buffer overwrite when extremely large files are processed on 32-bit builds (bsc#1272580). * CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). * CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of- file check (bsc#1272953). * Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
## This update for ImageMagick fixes the following issues: * CVE-2026-56365: memory leak in the PNG encoder when writing MNG images (bsc#1270004). * CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). * CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). * CVE-2026-62946: integer overflow in JNX decoder leading to heap buffer overwrite when extremely large files are processed on 32-bit builds (bsc#1272580). * CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). * CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of- file check (bsc#1272953). * Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
* CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56365 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56365 ( NVD ): 6.3
Announcement ID: SUSE-SU-2026:23312-1 Release Date: 2026-08-24T18:56:27Z Rating: moderate
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
