Hi,
The following vulnerabilities were published for imagemagick.
CVE-2026-86420[0]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower
| the memory budget when an operation inside OpenPixelCache fails.
| Repeated triggering of such failures can exhaust the process memory
| budget and result in a denial of service.
CVE-2026-86421[1]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in
| the MSL image decoder. A crafted MSL image triggers memory
| allocation without proper deallocation, allowing an attacker to
| exhaust memory and cause a denial of service.
CVE-2026-86423[2]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the GetList method of
| PerlMagick. A crafted call to the GetList method can trigger the
| use-after-free, resulting in a crash (denial of service).
CVE-2026-86424[3]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-
| time-of-use (TOCTOU) vulnerability in the video decoder that allows
| attackers to bypass path policy write restrictions via symlink
| swaps. An attacker can replace a symlink between policy validation
| (check-time) and the file write operation (use-time) to write to
| policy-denied locations.
CVE-2026-86425[4]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the Layer method of PerlMagick.
| An attacker who supplies a crafted list of images can trigger memory
| access after deallocation, resulting in a crash (denial of service).
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-86420
https://www.cve.org/CVERecord?id=CVE-2026-86420
[1] https://security-tracker.debian.org/tracker/CVE-2026-86421
https://www.cve.org/CVERecord?id=CVE-2026-86421
[2] https://security-tracker.debian.org/tracker/CVE-2026-86423
https://www.cve.org/CVERecord?id=CVE-2026-86423
[3] https://security-tracker.debian.org/tracker/CVE-2026-86424
https://www.cve.org/CVERecord?id=CVE-2026-86424
[4] https://security-tracker.debian.org/tracker/CVE-2026-86425
https://www.cve.org/CVERecord?id=CVE-2026-86425
Regards,
Salvatore