#1150337 imagemagick: CVE-2026-106564 CVE-2026-106565 CVE-2026-106566 CVE-2026-106567 CVE-2026-106568 CVE-2026-106569 CVE-2026-106570

Package:
src:imagemagick
Source:
src:imagemagick
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 19:01:06 UTC
Severity:
normal
Tags:
#1150337#5
Date:
2026-10-08 18:58:02 UTC
From:
To:
Hi,

The following vulnerabilities were published for imagemagick.

CVE-2026-106564[0]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, a crafted EXR image
| can cause the EXR decoder to write beyond a heap buffer, causing the
| process to crash. This issue is fixed in version 7.1.2-32.


CVE-2026-106565[1]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| missing end-of-file check while reading bzip2-compressed image data
| can cause an infinite loop and exhaust processing resources. This
| issue is fixed in versions 7.1.2-32 and 6.9.13-57.


CVE-2026-106566[2]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, delegate symlink
| cleanup does not check the MAGICK_SHRED_PASSES environment variable,
| allowing a local privileged workflow to overwrite a file with random
| data. This issue is fixed in version 7.1.2-32.


CVE-2026-106567[3]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| crafted PSD file can trigger an integer-conversion error in the PSD
| decoder on 32-bit builds, causing an infinite loop and denial of
| service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.


CVE-2026-106568[4]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a
| crafted XMP profile embedded in an image can cause the profile
| parser to enter an infinite loop, preventing image processing from
| completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.


CVE-2026-106569[5]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, missing validation
| and resource checks in the ASE decoder allow a crafted ASE image to
| cause a crash or a long-running operation. This issue is fixed in
| version 7.1.2-32.


CVE-2026-106570[6]:
| ImageMagick is free and open-source software used for editing and
| manipulating digital images. Prior to 7.1.2-32, an unauthenticated
| adjacent-network client can repeatedly connect to the distributed
| pixel cache server and exhaust its available connections, causing
| denial of service. This issue is fixed in version 7.1.2-32.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-106564
https://www.cve.org/CVERecord?id=CVE-2026-106564
[1] https://security-tracker.debian.org/tracker/CVE-2026-106565
https://www.cve.org/CVERecord?id=CVE-2026-106565
[2] https://security-tracker.debian.org/tracker/CVE-2026-106566
https://www.cve.org/CVERecord?id=CVE-2026-106566
[3] https://security-tracker.debian.org/tracker/CVE-2026-106567
https://www.cve.org/CVERecord?id=CVE-2026-106567
[4] https://security-tracker.debian.org/tracker/CVE-2026-106568
https://www.cve.org/CVERecord?id=CVE-2026-106568
[5] https://security-tracker.debian.org/tracker/CVE-2026-106569
https://www.cve.org/CVERecord?id=CVE-2026-106569
[6] https://security-tracker.debian.org/tracker/CVE-2026-106570
https://www.cve.org/CVERecord?id=CVE-2026-106570

Regards,
Salvatore