#1147176 imagemagick: CVE-2026-86420 CVE-2026-86421 CVE-2026-86423 CVE-2026-86424 CVE-2026-86425

Package:
src:imagemagick
Source:
src:imagemagick
Submitter:
Salvatore Bonaccorso
Date:
2026-09-08 19:49:02 UTC
Severity:
normal
Tags:
#1147176#5
Date:
2026-09-08 19:46:45 UTC
From:
To:
Hi,

The following vulnerabilities were published for imagemagick.

CVE-2026-86420[0]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower
| the memory budget when an operation inside OpenPixelCache fails.
| Repeated triggering of such failures can exhaust the process memory
| budget and result in a denial of service.


CVE-2026-86421[1]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in
| the MSL image decoder. A crafted MSL image triggers memory
| allocation without proper deallocation, allowing an attacker to
| exhaust memory and cause a denial of service.


CVE-2026-86423[2]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the GetList method of
| PerlMagick. A crafted call to the GetList method can trigger the
| use-after-free, resulting in a crash (denial of service).


CVE-2026-86424[3]:
| ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-
| time-of-use (TOCTOU) vulnerability in the video decoder that allows
| attackers to bypass path policy write restrictions via symlink
| swaps. An attacker can replace a symlink between policy validation
| (check-time) and the file write operation (use-time) to write to
| policy-denied locations.


CVE-2026-86425[4]:
| ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a
| heap-use-after-free vulnerability in the Layer method of PerlMagick.
| An attacker who supplies a crafted list of images can trigger memory
| access after deallocation, resulting in a crash (denial of service).


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86420
https://www.cve.org/CVERecord?id=CVE-2026-86420
[1] https://security-tracker.debian.org/tracker/CVE-2026-86421
https://www.cve.org/CVERecord?id=CVE-2026-86421
[2] https://security-tracker.debian.org/tracker/CVE-2026-86423
https://www.cve.org/CVERecord?id=CVE-2026-86423
[3] https://security-tracker.debian.org/tracker/CVE-2026-86424
https://www.cve.org/CVERecord?id=CVE-2026-86424
[4] https://security-tracker.debian.org/tracker/CVE-2026-86425
https://www.cve.org/CVERecord?id=CVE-2026-86425

Regards,
Salvatore