Skip to content
openSUSE ImageMagick and 7zip Vulnerabilities Lead to Denial of Service Risks

openSUSE ImageMagick and 7zip Vulnerabilities Lead to Denial of Service Risks

First seen 30 Jun 2026, 08:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 1, 2026 at 08:04 UTC

On June 30, 2026, openSUSE released advisories for critical vulnerabilities in ImageMagick and 7zip. ImageMagick has multiple CVEs including CVE-2026-45031 and CVE-2026-46520, leading to Denial of Service due to resource policy bypass and excessive resource use. 7zip also reported vulnerabilities such as CVE-2026-48092 and CVE-2026-48102, which allow for information disclosure and Denial of Service through crafted UDF images. These vulnerabilities affect openSUSE Leap 16.0 and could lead to significant disruptions if exploited. The vulnerabilities were published between June 5 and June 10, 2026, with patches available. Security professionals are urged to apply updates immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 97d ago How this analysis works

Timeline

2026-05-26
Public exploit for CVE-2026-48095 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-06-05
CVE-2026-48101 published
Information disclosure vulnerability in UEFI capsule parser disclosed affecting 7zip.
Linuxsecurity
2026-06-05
CVE-2026-48092 published
Heap memory disclosure vulnerability in 32-bit builds of 7zip published.
Linuxsecurity
2026-06-05
CVE-2026-48102 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48104 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48111 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48103 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
CVE-2026-48112 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-45031 published
Denial of Service vulnerability in ImageMagick due to resource policy bypass disclosed.
Linuxsecurity
2026-06-10
CVE-2026-46520 published
Denial of Service vulnerability via out-of-bounds write in ImageMagick disclosed.
Linuxsecurity

More articles in this cluster (5)

Following this threat?

Track OpenSUSE and CVE-2026-42326 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed