openSUSE ImageMagick and 7zip Vulnerabilities Lead to Denial of Service Risks

openSUSE ImageMagick and 7zip Vulnerabilities Lead to Denial of Service Risks

First seen 30 Jun 2026, 08:40 UTC Linuxsecurity 71% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

On June 30, 2026, openSUSE released advisories for critical vulnerabilities in ImageMagick and 7zip. ImageMagick has multiple CVEs including CVE-2026-45031 and CVE-2026-46520, leading to Denial of Service due to resource policy bypass and excessive resource use. 7zip also reported vulnerabilities such as CVE-2026-48092 and CVE-2026-48102, which allow for information disclosure and Denial of Service through crafted UDF images. These vulnerabilities affect openSUSE Leap 16.0 and could lead to significant disruptions if exploited. The vulnerabilities were published between June 5 and June 10, 2026, with patches available. Security professionals are urged to apply updates immediately to mitigate risks.

Key Points: • openSUSE has issued critical updates for vulnerabilities in ImageMagick and 7zip. • Multiple CVEs identified, including CVE-2026-45031 and CVE-2026-46520 for ImageMagick. • 7zip vulnerabilities include CVE-2026-48092 and CVE-2026-48102, posing serious risks.

ThreatCluster AI

Timeline

2026-05-26
Public exploit for CVE-2026-48095 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-05
CVE-2026-48101 published
Information disclosure vulnerability in UEFI capsule parser disclosed affecting 7zip.
Linuxsecurity
2026-06-05
CVE-2026-48092 published
Heap memory disclosure vulnerability in 32-bit builds of 7zip published.
Linuxsecurity
2026-06-05
CVE-2026-48102 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48104 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48111 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48103 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48112 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-45031 published
Denial of Service vulnerability in ImageMagick due to resource policy bypass disclosed.
Linuxsecurity
2026-06-10
CVE-2026-46520 published
Denial of Service vulnerability via out-of-bounds write in ImageMagick disclosed.
Linuxsecurity

Community

Browse all →