[Git][security-tracker-team/security-tracker][master] Add imagemagick issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 16 05:59:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
81b1f32d by Salvatore Bonaccorso at 2026-07-16T06:58:28+02:00
Add imagemagick issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -80,17 +80,31 @@ CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092 (7.1.2-26)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1 (6.9.13-51)
 CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4 (7.1.2-26)
 CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in co ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a (7.1.2-26)
 CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memo ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec (7.1.2-26)
 CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disc ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6 (7.1.2-26)
 CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vu ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64 (7.1.2-26)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc (6.9.13-51)
 CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a p ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27 (7.1.2-26)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012 (6.9.13-51)
 CVE-2026-61841
 	REJECTED
 CVE-2026-61839
@@ -124,7 +138,10 @@ CVE-2026-61606
 CVE-2026-61605
 	REJECTED
 CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer ...)
-	TODO: check
+	- imagemagick 8:7.1.2.26+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/378bfc12bf7bbc4d9ab081120873efef935ebd85 (7.1.2-26)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d0aa5c9e09e0cf5e400309ca76ae886a980b0555 (6.9.13-51)
 CVE-2026-61457 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a  ...)
 	TODO: check
 CVE-2026-61453 (Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b1f32daf02cf2364d8e79613c668be403c0634

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b1f32daf02cf2364d8e79613c668be403c0634
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260716/f222d24c/attachment.htm>


More information about the debian-security-tracker-commits mailing list