[Pkg-gmagick-im-team] imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.changes ACCEPTED into oldstable-proposed-updates->oldstable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Mon Jul 13 20:35:05 BST 2026


Thank you for your contribution to Debian.

Mapping oldstable-security to oldstable-proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 12 Jul 2026 10:37:54 +0200
Source: imagemagick
Architecture: source
Version: 8:6.9.11.60+dfsg-1.6+deb12u12
Distribution: bookworm-security
Urgency: high
Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team at lists.alioth.debian.org>
Changed-By: Bastien Roucariès <rouca at debian.org>
Changes:
 imagemagick (8:6.9.11.60+dfsg-1.6+deb12u12) bookworm-security; urgency=high
 .
   * Backport policy from 6.9.13-58
   * Fix CVE-2026-53466:
     An integer overflow in the XCF decoder can result in an out of bounds
     read when a crafted image is read, potentially resulting in a crash.
   * Fix CVE-2026-53467:
     The MNG decoder contains a possible heap information disclosure
     vulnerability because part of the pixels are left unchanged.
   * Backport draw.c from 6.9.13-52
   * Fix CVE-2026-55577:
     A heap buffer overflow occurs in the MVG decoder that could result
     in an out of bounds write when processing a crafted image.
   * Fix CVE-2026-55594:
     A missing depth check in the MVG decoder will result in
     a stack overflow when a crafted image is provided
   * Fix CVE-2026-55595
     When providing invalid arguments to the connected-components option
     an infinite loop will occur.
   * Fix CVE-2026-55597:
     An incorrect handling of arguments can cause a heap buffer over-write
     in the JP2 encoder
   * Fix CVE-2026-55628:
     The `-concatenate` operation is missing policy checks, potentially
     resulting in both reading and writing to paths disallowed by the
     security policy
   * Fix CVE-2026-56361:
     Attackers can trigger heap buffer overflow by providing incorrect
     morphology parameters causing single pixel memory access violations.
   * Fix CVE-2026-56363:
     A division by zero vulnerability in binomial kernel processing
     that allows attackers to cause denial of service.
   * Fix CVE-2026-56365:
     A memory leak vulnerability in the PNG encoder when writing MNG images.
     Attackers can trigger the encoder failure condition to exhaust memory
     resources and cause denial of service.
   * Fix CVE-2026-56366:
     A memory leak vulnerability in the META reader when processing APP1JPEG
     input paths. Attackers can trigger this memory leak by providing specially
     crafted APP1JPEG image files, causing denial of service through resource
     exhaustion.
   * Fix CVE-2026-56367:
     An integer overflow in the PSB (PSD v2) RLE decoding path
     (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds
     read on 32-bit builds.
   * Fix CVE-2026-56368:
     A memory leak vulnerability in multiple coders that write raw pixel
     data where allocated objects are not properly freed. Attackers
     can trigger this leak by processing specially crafted images,
     causing memory exhaustion and denial of service.
   * Fix CVE-2026-56370
     An out-of-bounds access vulnerability in ConnectedComponentsImage()
     when processing connected-components artifacts with invalid indices.
   * Fix CVE-2026-56371
     a memory leak in coders/txt.c when processing TXT files with texture
     attributes: the texture object allocated via ReadImage is not released
     when GetTypeMetrics fails, leaking memory each time a crafted
     TXT file with a texture attribute is processed.
   * Fix CVE-2026-56373:
     A use-after-free vulnerability in the PDB decoder that uses a stale
     pointer when memory allocation fails. Attackers can trigger this vulnerability
     by processing malicious PDB files to cause crashes or write
     a single zero byte to freed memory.
   * Fix CVE-2026-56376:
     A heap use-after-free in the meta coder: when memory allocation fails,
     a single byte is written to a stale pointer.
   * Fix CVE-2026-56377:
     An incorrect policy check that allows attackers to create or truncate files
     disallowed by security policies. Remote attackers can bypass path policy
     restrictions in sandboxed conversion services to write arbitrary files outside
     intended boundaries.
   * Fix CVE-2026-56378:
     A heap out-of-bounds read in the PCD coder's DecodeImage loop.
     A crafted PCD file can trigger a one-byte heap out-of-bounds read during
     image decoding, resulting in denial of service and potential
     disclosure of an adjacent heap byte.
Checksums-Sha1:
 aa7a65985d164b375ff1b5a6e8eaa5a4e451b8d0 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc
 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz
 a8c3ef07242db0e4961bf2783f2508a0ce95f26a 364080 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz
 a1fa42e1e187341ca7735ccb94694203b29ea201 8959 imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo
Checksums-Sha256:
 4844f37c6b27017735efe4844729ff4263e3756e7b127214859e89008b4db914 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc
 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz
 c1327baa694029b2447ff0cf9124f40dcdc58a518964fa6bcde86f2ae9addbb7 364080 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz
 6fa5fd58c3c20ce6ee1eb11028b840f6bc3dbe04bcf9b28229521b642851980a 8959 imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo
Files:
 fa198e9e5616deb9229504625ebe08d9 5134 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc
 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz
 c889a4208ac9dfffdecdb48ca351d07e 364080 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz
 f41d9a3c692bf18c94f65f3659ae7a8f 8959 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmpUzhUACgkQADoaLapB
CF/BPhAAq3UOk+SFkkBQ0NFt/+gBEkj6/lHKhvJfHdDIaF+X9cAsmI0wPu+KLuFK
cQFK5GLY4iZ68ttUSwfGvS0VEt0Sde9WRoIOeO5Yj9Bk2wjGIsdGCCsV2GFjrwT9
TaYKa6OepSAuzfl5X0Z2SxmuGCkUhA6aS5b5pBX0ReWEc0gvL7BZsNMlqZ9/a7h5
MUrFjZXzTvdKr2rZ9Ug/ARgQLeANXHAyPPzjJCQ8wuiJnuOCoTHnPRU6spGQxX2d
OBHsGu4+tU2wI2rFQd7lxDOvCOA1U6EQq3+Rmtr4OQIc4KdMTw4Z6lEQFxvhRciU
13dg8BsNU8CpXgD8Z59E9S4pDwj0KVGbQpIG5c5tndfhM5tG+lo6ybsxQk1DTQFm
eeGYtOcwkF+YFRFkcdAT9YdYb889gD3saWuFK/Lgz+oD9yj9mSgpfqagKHy5ohhz
/CwuyTbaAkcda0IIxYc0WehDJG0NLtKdOa8Tu5DzoAdNfcYEAfbb1qyguc7+Qhv1
kbURBhmnQ8DOkBO6LPtlGM+El2pzNOkCRLRb+LfLKn0quKFo09iqCXtf2h2BUiud
yu6T7LxrOc4ryyAXgkceYBEbHzVQJLL9APl21Jxv1PAXyR+aO73xEgLb6nKJOT0V
cgH+yWdDbQWorIPXomTayE0FfYpEw4y5MQ8J9u7/4KTY4nK5GRY=
=qbiA
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gmagick-im-team/attachments/20260713/a49db03b/attachment.sig>


More information about the Pkg-gmagick-im-team mailing list