Multiple Vulnerabilities in Linux ImageMagick and Emacs Software

Multiple Vulnerabilities in Linux ImageMagick and Emacs Software

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Recent updates for ImageMagick and Emacs have addressed several vulnerabilities affecting Linux systems. ImageMagick's update (SUSE-2026-23312) resolves multiple issues, including CVE-2026-56365, a memory leak in the PNG encoder, and CVE-2026-62343, a heap buffer overwrite during morphology operations. Emacs's update (openSUSE-2026-21711) fixes vulnerabilities such as CVE-2026-77219, which allows arbitrary code execution through specially crafted files. The updates are critical for users of SUSE and openSUSE distributions. Attack vectors include crafted images and filenames, which can lead to memory leaks and code execution. Both updates are rated moderate to important, emphasizing the need for timely patching. Users are advised to apply the updates using recommended methods like YaST or zypper.

Key Points: • ImageMagick and Emacs updates fix critical vulnerabilities affecting Linux systems. • Key CVEs include CVE-2026-56365 and CVE-2026-77219, with potential for memory leaks and code execution. • Users are urged to apply patches immediately to mitigate risks.

Timeline

2026-02-24
CVE-2026-25797 published
A code injection vulnerability in the HTML encoder was disclosed, affecting ImageMagick.
Linuxsecurity
2026-06-30
CVE-2026-56365 published
Memory leak vulnerability in the PNG encoder of ImageMagick was published.
Linuxsecurity
2026-07-25
CVE-2026-66011 published
Memory leak in the command-line interface of ImageMagick was disclosed.
Linuxsecurity
2026-07-29
CVE-2026-64685 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-29
CVE-2026-62343 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-62946 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-62363 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-21
CVE-2026-77219 published
Integer overflow vulnerability in Emacs's image loader was disclosed, leading to memory leaks.
Linuxsecurity
2026-08-25
CVE-2026-79992 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-31
ImageMagick update released
SUSE released an update addressing multiple vulnerabilities in ImageMagick, including CVE-2026-56365.
Linuxsecurity