OESA-2026-2144

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2144
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2144
Upstream
  • CVE-2026-42050
Published
2026-05-03T09:55:59Z
Modified
2026-05-03T10:19:27.776596Z
Summary
ImageMagick security update
Details

Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.

Security Fix(es):

ImageMagick contains a stack buffer overflow vulnerability in the XTileImage function. An attacker could exploit this vulnerability by crafting a malicious image file, potentially leading to arbitrary code execution or program crash due to stack overflow.(CVE-2026-42050)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
ImageMagick

Package

Name
ImageMagick
Purl
pkg:rpm/openEuler/ImageMagick&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.9.13.46-1.oe2003sp4

Ecosystem specific

{
    "x86_64": [
        "ImageMagick-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-c++-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-c++-devel-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-debuginfo-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-debugsource-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-devel-6.9.13.46-1.oe2003sp4.x86_64.rpm",
        "ImageMagick-perl-6.9.13.46-1.oe2003sp4.x86_64.rpm"
    ],
    "src": [
        "ImageMagick-6.9.13.46-1.oe2003sp4.src.rpm"
    ],
    "noarch": [
        "ImageMagick-help-6.9.13.46-1.oe2003sp4.noarch.rpm"
    ],
    "aarch64": [
        "ImageMagick-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-c++-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-c++-devel-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-debuginfo-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-debugsource-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-devel-6.9.13.46-1.oe2003sp4.aarch64.rpm",
        "ImageMagick-perl-6.9.13.46-1.oe2003sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json"
openEuler:22.03-LTS-SP4
ImageMagick

Package

Name
ImageMagick
Purl
pkg:rpm/openEuler/ImageMagick&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.2.21-1.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "ImageMagick-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2203sp4.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2203sp4.x86_64.rpm"
    ],
    "src": [
        "ImageMagick-7.1.2.21-1.oe2203sp4.src.rpm"
    ],
    "noarch": [
        "ImageMagick-help-7.1.2.21-1.oe2203sp4.noarch.rpm"
    ],
    "aarch64": [
        "ImageMagick-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2203sp4.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2203sp4.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json"
openEuler:24.03-LTS
ImageMagick

Package

Name
ImageMagick
Purl
pkg:rpm/openEuler/ImageMagick&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.2.21-1.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "ImageMagick-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403.x86_64.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "ImageMagick-7.1.2.21-1.oe2403.src.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp1.src.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "ImageMagick-help-7.1.2.21-1.oe2403.noarch.rpm",
        "ImageMagick-help-7.1.2.21-1.oe2403sp1.noarch.rpm",
        "ImageMagick-help-7.1.2.21-1.oe2403sp3.noarch.rpm"
    ],
    "aarch64": [
        "ImageMagick-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403.aarch64.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json"
openEuler:24.03-LTS-SP1
ImageMagick

Package

Name
ImageMagick
Purl
pkg:rpm/openEuler/ImageMagick&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.2.21-1.oe2403sp1

Ecosystem specific

{
    "x86_64": [
        "ImageMagick-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp1.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp1.x86_64.rpm"
    ],
    "src": [
        "ImageMagick-7.1.2.21-1.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "ImageMagick-help-7.1.2.21-1.oe2403sp1.noarch.rpm"
    ],
    "aarch64": [
        "ImageMagick-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp1.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp1.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json"
openEuler:24.03-LTS-SP3
ImageMagick

Package

Name
ImageMagick
Purl
pkg:rpm/openEuler/ImageMagick&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.2.21-1.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "ImageMagick-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp3.x86_64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp3.x86_64.rpm"
    ],
    "src": [
        "ImageMagick-7.1.2.21-1.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "ImageMagick-help-7.1.2.21-1.oe2403sp3.noarch.rpm"
    ],
    "aarch64": [
        "ImageMagick-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-c++-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-c++-devel-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-debuginfo-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-debugsource-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-devel-7.1.2.21-1.oe2403sp3.aarch64.rpm",
        "ImageMagick-perl-7.1.2.21-1.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2144.json"