[Git][security-tracker-team/security-tracker][master] Add new imagemagick issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 22:14:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6f3bc9db by Salvatore Bonaccorso at 2026-09-18T23:14:25+02:00
Add new imagemagick issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -107,15 +107,33 @@ CVE-2026-93592 (vLLM versions before 0.28.0 fail to validate the lower bound of
 CVE-2026-93591 (SiYuan versions before 3.8.3 contain an SQL injection vulnerability in ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-93590 (ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in  ...)
-	TODO: check
+	- imagemagick 8:7.1.2.31+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/59046410c17e9421f0ad7b4bec478a892cf30c12 (7.1.2-31)
 CVE-2026-93589 (ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero  ...)
-	TODO: check
+	- imagemagick 8:7.1.2.31+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/8f620237fe341e814430fe3621b867b0b615f446 (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/1e91833e30a88c104276dcfbc01bb68ac4528514 (6.9.13-56)
 CVE-2026-93588 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL point ...)
-	TODO: check
+	- imagemagick 8:7.1.2.31+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-92rw-c5mw-27v4
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c4b3c9039a1509e3e7869331773865b521a62f93 (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3b124bb81d3c53ec7d2b46f5ea04c00c4b07b9b3 (6.9.13-56)
 CVE-2026-93587 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy byp ...)
-	TODO: check
+	- imagemagick 8:7.1.2.31+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/d779ac52f92c3045ced59362b483bee25a3fc784 (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b5da5eac006bae77c587a7c238e346c90ea52acd (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/4332e26659c849bf126aecb215482de1eed73308 (6.9.13-56)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0d768346a13b63e4d791be4b798482abd1e050d5 (6.9.13-56)
 CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after- ...)
-	TODO: check
+	- imagemagick 8:7.1.2.31+dfsg1-1
+	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/282f455de5c80a7a0d1a713087db9c8fce344141 (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4fe31106f41fa114945ceaf93226fb151ada0d19 (7.1.2-31)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3e0ff6b63c37844732a4f79700bc58ac5370fa25 (6.9.13-56)
+	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/742ee222f6df8e7512755a8939b16b90a034a9a7 (6.9.13-56)
 CVE-2026-93579 (A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a  ...)
 	TODO: check
 CVE-2026-93578 (A flaw was found in Netty's Online Certificate Status Protocol (OCSP)  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3bc9db89da3e1fe6e11bc32eab70e2914cf44a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6f3bc9db89da3e1fe6e11bc32eab70e2914cf44a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/d9492aeb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list