[Git][security-tracker-team/security-tracker][master] 2 commits: Imagemagick/triagging
Bastien Roucariès (@rouca)
rouca at debian.org
Wed Jul 22 15:39:06 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
412897e3 by Bastien Roucariès at 2026-07-22T16:18:37+02:00
Imagemagick/triagging
Some fix are on jumbo patch
- - - - -
d86256f9 by Bastien Roucariès at 2026-07-22T16:37:35+02:00
CVE-2026-61867/imagemagick
This is an im7 only bug:
- according to cve report
- by code analysis
- by introducing commit
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -8013,8 +8013,11 @@ CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains
CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <not-affected> (vulnerable code introduced later)
+ [bullseye] - imagemagick <not-affected> (vulnerable code introduced later)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30 (7.1.2-26)
+ NOTE: Introduced by https://github.com/ImageMagick/ImageMagick/commit/14c08dcd1910ecd8360f51d13885b2c9c39b655d (7.0.1-0)
CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
@@ -8026,25 +8029,29 @@ CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4 (7.1.2-26)
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
+ NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61864, CVE-2026-61863
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in co ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a (7.1.2-26)
+ NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
+ NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61861, CVE-2026-61865
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memo ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
- NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862
+ NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, CVE-2026-61864, CVE-2026-61865
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disc ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
- NOTE: For imagemagick 6 patch include fix fro CVE-2026-61863
+ NOTE: For imagemagick 6 patch include fix for CVE-2026-61863, CVE-2026-61864
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vu ...)
- imagemagick 8:7.1.2.26+dfsg1-1
[trixie] - imagemagick <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bd8f4a533604617afe3267a1ec93893716ecf2fa...d86256f991d0c27a0181f18eeb706514da1f7d15
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bd8f4a533604617afe3267a1ec93893716ecf2fa...d86256f991d0c27a0181f18eeb706514da1f7d15
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/91d245ba/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list