[Pkg-gmagick-im-team] Bug#1147176: imagemagick: CVE-2026-86420 CVE-2026-86421 CVE-2026-86423 CVE-2026-86424 CVE-2026-86425

Salvatore Bonaccorso carnil at debian.org
Tue Sep 8 20:46:45 BST 2026


Source: imagemagick
Version: 8:7.1.2.29+dfsg2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerabilities were published for imagemagick.

CVE-2026-86420[0]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower
| the memory budget when an operation inside OpenPixelCache fails.
| Repeated triggering of such failures can exhaust the process memory
| budget and result in a denial of service.


CVE-2026-86421[1]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in
| the MSL image decoder. A crafted MSL image triggers memory
| allocation without proper deallocation, allowing an attacker to
| exhaust memory and cause a denial of service.


CVE-2026-86423[2]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the GetList method of
| PerlMagick. A crafted call to the GetList method can trigger the
| use-after-free, resulting in a crash (denial of service).


CVE-2026-86424[3]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-
| time-of-use (TOCTOU) vulnerability in the video decoder that allows
| attackers to bypass path policy write restrictions via symlink
| swaps. An attacker can replace a symlink between policy validation
| (check-time) and the file write operation (use-time) to write to
| policy-denied locations.


CVE-2026-86425[4]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the Layer method of PerlMagick.
| An attacker who supplies a crafted list of images can trigger memory
| access after deallocation, resulting in a crash (denial of service).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86420
    https://www.cve.org/CVERecord?id=CVE-2026-86420
[1] https://security-tracker.debian.org/tracker/CVE-2026-86421
    https://www.cve.org/CVERecord?id=CVE-2026-86421
[2] https://security-tracker.debian.org/tracker/CVE-2026-86423
    https://www.cve.org/CVERecord?id=CVE-2026-86423
[3] https://security-tracker.debian.org/tracker/CVE-2026-86424
    https://www.cve.org/CVERecord?id=CVE-2026-86424
[4] https://security-tracker.debian.org/tracker/CVE-2026-86425
    https://www.cve.org/CVERecord?id=CVE-2026-86425

Regards,
Salvatore



More information about the Pkg-gmagick-im-team mailing list