Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.
Security Fix(es):
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerability allows an attacker to perform an out of bounds via a specially crafted image. This vulnerability is fixed in 7.1.2-16.(CVE-2026-28493)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow exists in ImageMagick's morphology kernel parsing functions. User-controlled kernel strings exceeding a buffer are copied into fixed-size stack buffers via memcpy without bounds checking, resulting in stack corruption. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28494)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28686)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28687)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28688)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path" authorization is checked before final file open/use. A symlink swap between check-time and use-time bypasses policy-denied read/write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28689)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a stack buffer overflow vulnerability exists in the MNG encoder. There is a bounds checks missing that could corrupting the stack with attacker-controlled data. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28690)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28691)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MAT decoder uses 32-bit arithmetic due to incorrect parenthesization resulting in a heap over-read. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28692)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-28693)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an extremely large image profile could result in a heap overflow when encoding a PNG image. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-30883)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-30929)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, a heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write. This vulnerability is fixed in 7.1.2-16.(CVE-2026-30931)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a crafted image could cause an out of bounds heap write inside the WaveletDenoiseImage method. When processing a crafted image with the -wavelet-denoise operation an out of bounds write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-30936)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.(CVE-2026-30937)
A stack buffer overflow vulnerability exists in the sixel encoder of ImageMagick software. Attackers can cause buffer overflow through specially crafted image files, potentially leading to arbitrary code execution or service crash.(CVE-2026-32259)
{
"severity": "High"
}{
"aarch64": [
"ImageMagick-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-c++-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-c++-devel-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-debuginfo-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-debugsource-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-devel-7.1.2.16-1.oe2203sp4.aarch64.rpm",
"ImageMagick-perl-7.1.2.16-1.oe2203sp4.aarch64.rpm"
],
"x86_64": [
"ImageMagick-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-c++-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-c++-devel-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-debuginfo-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-debugsource-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-devel-7.1.2.16-1.oe2203sp4.x86_64.rpm",
"ImageMagick-perl-7.1.2.16-1.oe2203sp4.x86_64.rpm"
],
"noarch": [
"ImageMagick-help-7.1.2.16-1.oe2203sp4.noarch.rpm"
],
"src": [
"ImageMagick-7.1.2.16-1.oe2203sp4.src.rpm"
]
}