Hi,
The following vulnerabilities were published for imagemagick.
CVE-2026-106564[0]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, a crafted EXR image
| can cause the EXR decoder to write beyond a heap buffer, causing the
| process to crash. This issue is fixed in version 7.1.2-32.
CVE-2026-106565[1]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| missing end-of-file check while reading bzip2-compressed image data
| can cause an infinite loop and exhaust processing resources. This
| issue is fixed in versions 7.1.2-32 and 6.9.13-57.
CVE-2026-106566[2]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, delegate symlink
| cleanup does not check the MAGICK_SHRED_PASSES environment variable,
| allowing a local privileged workflow to overwrite a file with random
| data. This issue is fixed in version 7.1.2-32.
CVE-2026-106567[3]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| crafted PSD file can trigger an integer-conversion error in the PSD
| decoder on 32-bit builds, causing an infinite loop and denial of
| service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
CVE-2026-106568[4]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| crafted XMP profile embedded in an image can cause the profile
| parser to enter an infinite loop, preventing image processing from
| completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
CVE-2026-106569[5]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, missing validation
| and resource checks in the ASE decoder allow a crafted ASE image to
| cause a crash or a long-running operation. This issue is fixed in
| version 7.1.2-32.
CVE-2026-106570[6]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, an unauthenticated
| adjacent-network client can repeatedly connect to the distributed
| pixel cache server and exhaust its available connections, causing
| denial of service. This issue is fixed in version 7.1.2-32.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-106564
https://www.cve.org/CVERecord?id=CVE-2026-106564
[1] https://security-tracker.debian.org/tracker/CVE-2026-106565
https://www.cve.org/CVERecord?id=CVE-2026-106565
[2] https://security-tracker.debian.org/tracker/CVE-2026-106566
https://www.cve.org/CVERecord?id=CVE-2026-106566
[3] https://security-tracker.debian.org/tracker/CVE-2026-106567
https://www.cve.org/CVERecord?id=CVE-2026-106567
[4] https://security-tracker.debian.org/tracker/CVE-2026-106568
https://www.cve.org/CVERecord?id=CVE-2026-106568
[5] https://security-tracker.debian.org/tracker/CVE-2026-106569
https://www.cve.org/CVERecord?id=CVE-2026-106569
[6] https://security-tracker.debian.org/tracker/CVE-2026-106570
https://www.cve.org/CVERecord?id=CVE-2026-106570
Regards,
Salvatore