SUSE-SU-2026:4334-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4334-1
SUSE-SU-2026:4334-1
Summary: Security update for ImageMagick
Details: This update for ImageMagick fixes the following issues: - CVE-2026-86420: denial of Service due to memory budget exhaustion (bsc#1279696). - CVE-2026-86421: denial of Service via memory leak in MSL decoder (bsc#1279711). - CVE-2026-86423: denial of service via heap-use-after-free in PerlMagick's GetList method (bsc#1279794). - CVE-2026-86425: denial of Service due to heap-use-after-free vulnerability (bsc#1279797).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264334-1/, https://bugzilla.suse.com/1279696, https://bugzilla.suse.com/1279711, https://bugzilla.suse.com/1279794, https://bugzilla.suse.com/1279797, https://www.suse.com/security/cve/CVE-2026-86420, https://www.suse.com/security/cve/CVE-2026-86421, https://www.suse.com/security/cve/CVE-2026-86423, https://www.suse.com/security/cve/CVE-2026-86425
Affected packages
Package
Name: ImageMagick
Purl: pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
