MGASA-2026-0414

Source
https://advisories.mageia.org/MGASA-2026-0414.html
Import Source
https://advisories.mageia.org/MGASA-2026-0414.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0414
Upstream
Published
2026-09-17T14:10:41Z
Modified
2026-09-17T14:15:02Z
Summary
Updated imagemagick package fixes security vulnerabilities
Details

Heap-use-after-free in Layer method of PerlMagick could result in a crash Path Policy TOCTOU symlink race bypass in the video decoder Heap-use-after-free in the GetList method of PerlMagick could result in a crash Memory Leak in MSL decoder Denial of service when exhausting the process memory budget Policy Bypass in UHDR encoder Division by Zero in FLIF encoder Null Pointer Dereference in PNM coder when hitting a memory limit Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option. Use after free in ImagesToBlob method

References
Credits

Affected packages

Mageia:10 / imagemagick

Package

Name
imagemagick
Purl
pkg:rpm/mageia/imagemagick?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.1.2.31-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0414.json"

Mageia:10 / imagemagick

Package

Name
imagemagick
Purl
pkg:rpm/mageia/imagemagick?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.1.2.31-1.mga10.tainted

Ecosystem specific

{
    "section": "tainted"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0414.json"