Critical ImageMagick Vulnerabilities Affect Multiple Ubuntu Versions

Critical ImageMagick Vulnerabilities Affect Multiple Ubuntu Versions

First seen 22 Jul 2026, 02:53 UTC UbuntuLinuxsecurityubuntu.com 90% similarity 70.5

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were discovered in ImageMagick, affecting Ubuntu versions 14.04 LTS through 24.04 LTS. The vulnerabilities include a stack overflow (CVE-2025-68950) and a use-after-free condition (CVE-2026-28688), both potentially leading to denial of service or arbitrary code execution. Additionally, CVE-2026-33900 involves an integer overflow that can cause out-of-bounds heap writes. These vulnerabilities were reported in July 2026, with the earliest CVE published in December 2025. Users are advised to update their systems to mitigate these risks. The vulnerabilities are particularly concerning due to their potential impact on a wide range of systems. The advisory emphasizes the importance of applying least privilege across Linux systems to reduce security risks.

Key Points: • ImageMagick vulnerabilities affect Ubuntu 14.04 LTS to 24.04 LTS. • CVE-2025-68950 and CVE-2026-28688 can lead to denial of service or arbitrary code execution. • Immediate system updates are recommended to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2025-12-30
CVE-2025-68950 published
ImageMagick vulnerability discovered allowing stack overflow, affecting multiple Ubuntu versions.
Linuxsecurity
2026-03-09
CVE-2026-28688 published
Use-after-free vulnerability in ImageMagick reported, impacting several Ubuntu versions.
Ubuntu
2026-04-13
CVE-2026-33900 published
Integer overflow vulnerability in ImageMagick identified, leading to potential denial of service.
Ubuntu
2026-04-13
CVE-2026-33905 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-20
ImageMagick vulnerabilities disclosed
Ubuntu released advisory USN-8558-1 detailing critical vulnerabilities in ImageMagick.
Ubuntu
2026-07-21
Further details on vulnerabilities published
Linuxsecurity provided additional insights on the vulnerabilities and recommended updates for affected systems.
Linuxsecurity

Community

Browse all →