Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f8f9cfff by Salvatore Bonaccorso at 2026-09-07T22:59:22+02:00
Add new imagemagick issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -109,17 +109,33 @@ CVE-2026-86427 (LibreNMS before 26.8.0 contains an 
argument injection vulnerabil
 CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass 
vulnerability ...)
        NOT-FOR-US: LibreNMS
 CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 
contains a heap ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d
 (7.1.2-30)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48
 (6.9.13-55)
 CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a 
time-of-check-tim ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69
 (7.1.2-30)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3
 (6.9.13-55)
 CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 
contains a heap ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8
 (7.1.2-30)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470
 (6.9.13-55)
 CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a 
time-of-check-time-of-use vulne ...)
-       TODO: check
+       - imagemagick <not-affected> (Only affects ImageMagick on Windows)
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
 CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory 
leak in th ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb
 (7.1.2-30)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680
 (6.9.13-55)
 CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly 
lower the  ...)
-       TODO: check
+       - imagemagick <unfixed>
+       NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154
 (7.1.2-30)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245
 (6.9.13-55)
 CVE-2026-86419 (Affected versions of MISP contain insufficient validation of 
server-si ...)
        - misp <itp> (bug #1144317)
 CVE-2026-86418 (Affected versions of MISP expose organisation metadata through 
the das ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8f9cfffc8a7df7ffa91bb7439c5d2d5766773ea

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f8f9cfffc8a7df7ffa91bb7439c5d2d5766773ea
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to