Le samedi 1 août 2026, 09:44:48 heure d’été d’Europe centrale Sylvain Beucler a 
écrit :
> Hi,
> 
> On 31/07/2026 21:33, Bastien Roucaries wrote:
> > imagemagick
> > --------------------
> > 
> > Release two DLA:
> > DLA 4680-1 fixing:
> > CVE-2026-53466 CVE-2026-53467 CVE-2026-55577 CVE-2026-55594
> >   CVE-2026-55595 CVE-2026-55597 CVE-2026-55628 CVE-2026-56361
> > CVE-2026-56363 CVE-2026-56365 CVE-2026-56366 CVE-2026-56367
> > CVE-2026-56368 CVE-2026-56370 CVE-2026-56371 CVE-2026-56373
> > CVE-2026-56376 CVE-2026-56377 CVE-2026-56378
> > 
> > DLA 4696-1 fixing
> > CVE-2026-61464 CVE-2026-61465 CVE-2026-61857 CVE-2026-61858
> > CVE-2026-61859 CVE-2026-61860 CVE-2026-61862 CVE-2026-61863
> > CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61868
> > CVE-2026-61869 CVE-2026-61870 CVE-2026-61872
> > 
> > DSA 6383-1 fixing
> > CVE-2026-53466 CVE-2026-53467 CVE-2026-55577 CVE-2026-55594
> > CVE-2026-55597 CVE-2026-55628 CVE-2026-56361 CVE-2026-56363
> > CVE-2026-56364 CVE-2026-56365 CVE-2026-56367 CVE-2026-56368
> >   CVE-2026-56370 CVE-2026-56371 CVE-2026-56376 CVE-2026-56377
> >   CVE-2026-56378
> > 
> > Proposed a PU fixing remaining CVE #1142554 trixie-pu: package 
> > imagemagick/8:7.1.1.43+dfsg1-1+deb13u12
> > 
> > For ELTS I released ELA-1766-1, ELA-1768-1 , ELA-1776-1, ELA-1778-1, 
> > ELA-1789-1
> > 
> > 
> > As usual with imagemagick progress was slow due to being ported between two 
> > majors version.
> 
> It seems we're piling more and more CVE imagemagick fixes, with 150 to 
> 250 patches per Debian dist, which I believe is hazardous in its own 
> right (and costly).
> 
> Do you think we should limit imagemagick fixes to moderate/high CVEs, 
> e.g. ignoring DoS/leaks?
Do not know some patch are really simple, sometimes I backport whole function, 
or even whole file
The main problem is that some coders are I think difficult to fixes like svg or 
tiff for some version

I have mixed filling about this for jessie, we do not backport a lot of fixes 
but during some major fixes I was forced to backport ten or more other patches.

Here for instance I am blocked for stretch on CVE-2026-56379 fixes, I am tented 
to ignore by CVE score is big

We have this kind of problem during the american fuzzer era when imagemagick 
was massively fuzed and we get about 300 CVEs opened. I believe it is more a 
matter a kind of software (image treatment with insecure format) then a proper 
problem.

Note that also imagmeagick upstream do not open CVE for every security report, 
they consider for instance that some insecure behavior could be render secure 
by correct policy and thus refuse to open CVE. I suppose we get about one third 
of upstream report downstream.

Depends also of the usage imagemagick through phpmagick or ruby with leak are a 
good way to get down a webserver.

rouca
> 
> Cheers!
> Sylvain
> 

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to