Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8592-1: ImageMagick vulnerabilities

Multiple vulnerabilities in ImageMagick allow attackers to achieve arbitrary code execution or denial of service via crafted image files; these include an out-of-bounds heap write during wavelet-denoise operations (CVE-2026-30936, CVSS 5.5), an out-of-bounds heap write with large XWD images (CVE-2026-30937, CVSS 6.8), and an integer overflow with large SFW images on 32-bit systems (CVE-2026-31853, CVSS 5.7). Affected versions are ImageMagick prior to 6.9.13-41 and versions 7.0.0-0 through 7.1.2-15. Users must upgrade to ImageMagick 6.9.13-41 or 7.1.2-16 to mitigate these risks.
Read Full Article →

Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-30936) It was discovered that ImageMagick incorrectly handled extremely large XWD images. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. (CVE-2026-30937) It was discovered that ImageMagick incorrectly handled extremely large SFW images on 32-bit systems. An attacker could possibly use this issue to trigger an integer overflow, resulting in a denial of service. (CVE-2026-31853) It was discovered that ImageMagick incorrectly handled memory allocation failures in the sixel encoder. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-32259)

Share this article