Source: imagemagick Version: 8:7.1.2.29+dfsg2-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for imagemagick. CVE-2026-86420[0]: | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower | the memory budget when an operation inside OpenPixelCache fails. | Repeated triggering of such failures can exhaust the process memory | budget and result in a denial of service. CVE-2026-86421[1]: | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in | the MSL image decoder. A crafted MSL image triggers memory | allocation without proper deallocation, allowing an attacker to | exhaust memory and cause a denial of service. CVE-2026-86423[2]: | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a | heap-use-after-free vulnerability in the GetList method of | PerlMagick. A crafted call to the GetList method can trigger the | use-after-free, resulting in a crash (denial of service). CVE-2026-86424[3]: | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check- | time-of-use (TOCTOU) vulnerability in the video decoder that allows | attackers to bypass path policy write restrictions via symlink | swaps. An attacker can replace a symlink between policy validation | (check-time) and the file write operation (use-time) to write to | policy-denied locations. CVE-2026-86425[4]: | ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a | heap-use-after-free vulnerability in the Layer method of PerlMagick. | An attacker who supplies a crafted list of images can trigger memory | access after deallocation, resulting in a crash (denial of service). If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-86420 https://www.cve.org/CVERecord?id=CVE-2026-86420 [1] https://security-tracker.debian.org/tracker/CVE-2026-86421 https://www.cve.org/CVERecord?id=CVE-2026-86421 [2] https://security-tracker.debian.org/tracker/CVE-2026-86423 https://www.cve.org/CVERecord?id=CVE-2026-86423 [3] https://security-tracker.debian.org/tracker/CVE-2026-86424 https://www.cve.org/CVERecord?id=CVE-2026-86424 [4] https://security-tracker.debian.org/tracker/CVE-2026-86425 https://www.cve.org/CVERecord?id=CVE-2026-86425 Regards, Salvatore

