[From nobody Thu Sep 10 20:51:05 2026
Received: (at submit) by bugs.debian.org; 8 Sep 2026 19:46:47 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 42; hammy, 148; neutral, 57; spammy,
 2. spammytokens:0.946-+--budget, 0.940-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--H*F:U*carnil, 0.000-+--H*Ad:N*Bug, 0.000-+--HTo:N*Debian
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1x41mI-00AkO8-13
 for submit@bugs.debian.org; Tue, 08 Sep 2026 19:46:47 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: imagemagick: CVE-2026-86420 CVE-2026-86421 CVE-2026-86423
 CVE-2026-86424 CVE-2026-86425
Message-ID: &lt;178889680536.1991309.12048287547379594885.reportbug@eldamar.lan&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Tue, 08 Sep 2026 21:46:45 +0200
Delivered-To: submit@bugs.debian.org

Source: imagemagick
Version: 8:7.1.2.29+dfsg2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerabilities were published for imagemagick.

CVE-2026-86420[0]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower
| the memory budget when an operation inside OpenPixelCache fails.
| Repeated triggering of such failures can exhaust the process memory
| budget and result in a denial of service.


CVE-2026-86421[1]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in
| the MSL image decoder. A crafted MSL image triggers memory
| allocation without proper deallocation, allowing an attacker to
| exhaust memory and cause a denial of service.


CVE-2026-86423[2]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the GetList method of
| PerlMagick. A crafted call to the GetList method can trigger the
| use-after-free, resulting in a crash (denial of service).


CVE-2026-86424[3]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-
| time-of-use (TOCTOU) vulnerability in the video decoder that allows
| attackers to bypass path policy write restrictions via symlink
| swaps. An attacker can replace a symlink between policy validation
| (check-time) and the file write operation (use-time) to write to
| policy-denied locations.


CVE-2026-86425[4]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the Layer method of PerlMagick.
| An attacker who supplies a crafted list of images can trigger memory
| access after deallocation, resulting in a crash (denial of service).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86420
    https://www.cve.org/CVERecord?id=CVE-2026-86420
[1] https://security-tracker.debian.org/tracker/CVE-2026-86421
    https://www.cve.org/CVERecord?id=CVE-2026-86421
[2] https://security-tracker.debian.org/tracker/CVE-2026-86423
    https://www.cve.org/CVERecord?id=CVE-2026-86423
[3] https://security-tracker.debian.org/tracker/CVE-2026-86424
    https://www.cve.org/CVERecord?id=CVE-2026-86424
[4] https://security-tracker.debian.org/tracker/CVE-2026-86425
    https://www.cve.org/CVERecord?id=CVE-2026-86425

Regards,
Salvatore
]