Le mardi 21 juillet 2026, 21:22:30 heure d’été d’Europe centrale Salvatore 
Bonaccorso a écrit :
> Hi Bastien,
> 
> On Tue, Jul 21, 2026 at 07:10:50PM +0200, Bastien Roucaries wrote:
> > Package: release.debian.org
> > Severity: normal
> > Tags: trixie
> > X-Debbugs-Cc: [email protected], [email protected]
> > Control: affects -1 + src:imagemagick
> > User: [email protected]
> > Usertags: pu
> > 
> > 
> > [ Reason ]
> > About 22 low impact CVEs
> > 
> > [ Impact ]
> > CVE are not closed
> > 
> > [ Tests ]
> > Automatic
> > 
> > [ Risks ]
> > Low
> > 
> > [ Checklist ]
> >   [X] *all* changes are documented in the d/changelog
> >   [X] I reviewed all changes and I approve them
> >   [X] attach debdiff against the package in (old)stable
> >   [X] the issue is verified as fixed in unstable
> > 
> > [ Changes ]
> > See changelog all CVE are closed
> > 
> > [ Other info ]
> > security team and myself think it is a good idea to upload quickly, in 
> > order to
> > not have a lot of CVE piled up.
> > 
> > Debusine: https://debusine.debian.net/debian/developers/work-request/932300/
> > 
> 
> > diff -Nru imagemagick-7.1.1.43+dfsg1/debian/changelog 
> > imagemagick-7.1.1.43+dfsg1/debian/changelog
> > --- imagemagick-7.1.1.43+dfsg1/debian/changelog     2026-06-20 
> > 11:35:39.000000000 +0000
> > +++ imagemagick-7.1.1.43+dfsg1/debian/changelog     2026-07-21 
> > 07:55:59.000000000 +0000
> > @@ -1,3 +1,152 @@
> > +imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium
> > +
> > +  * Fix CVE-2026-56362:
> > +    A heap-buffer-overflow read vulnerability in GetPixelIndex caused
> > +    by OpenPixelCache updating image channel metadata before pixel
> > +    cache memory allocation. Attackers can trigger memory and
> > +    disk allocation failures to cause a heap-buffer-overflow
> > +    read affecting any writer calling GetPixelIndex.
> > +  * Fix CVE-2026-56366:
> > +    A memory leak vulnerability in the META reader
> > +    when processing APP1JPEG input paths.
> > +  * Fix CVE-2026-56372:
> > +    A heap buffer overflow vulnerability in the magnify operation
> > +    that allows attackers to read out of bounds memory.
> > +  * Fix CVE-2026-56373:
> > +    A use-after-free vulnerability in the PDB decoder that
> > +    uses a stale pointer when memory allocation fails.
> > +  * Fix CVE-2026-56374:
> > +    A heap buffer overflow vulnerability in the FTXT encoder
> > +    due to missing boundary checks when parsing ftxt:format.
> > +  * Fix CVE-2026-56375:
> > +    A memory leak vulnerability in the ASHLAR coder when
> > +    an action fails
> > +  * Fix CVE-2026-61464:
> > +    A heap-based buffer over-write vulnerability that occurs
> > +    when running an X11 import with a crafted window title.
> > +  * Fix CVE-2026-61465:
> > +    A missing a check was found, for the allowed memory allocation
> > +    limit in matrix-backed operations such as -canny.
> > +  * Fix CVE-2026-61857:
> > +    A heap use-after-free vulnerability caused by missing null
> > +    check when parsing XMP profiles.
> > +  * Fix CVE-2026-61858:
> > +    A policy bypass vulnerability in the APNG encoder and
> > +    external delegates due to missing validation checks.
> > +  * Fix CVE-2026-61859:
> > +    A policy bypass vulnerability in the -script operation due
> > +    to missing security policy checks.
> > +  * Fix CVE-2026-61860:
> > +    a use-after-free vulnerability that occurs when freetype
> > +    initialization fails: the method does not exit and
> > +    continues to use memory that was already freed.
> > +  * Fix CVE-2026-61861:
> > +    A use-after-free vulnerability in the FormatMagickCaption method
> > +    when memory allocation fails.
> > +  * Fix CVE-2026-61862:
> > +    When a profile is displayed with the identify command and the
> > +    profile value is not printable, a single byte at the end of the
> > +    profile can be printed.
> > +  * Fix CVE-2026-61863:
> > +    A memory leak in the TIFF encoder that occurs when a temporary
> > +    file cannot be created, resulting in a small memory leak.
> > +  * Fix CVE-2026-61864:
> > +    A memory leak in color transformation to the log colorspace:
> > +    when the operation fails, a small amount of memory is not released.
> > +  * Fix CVE-2026-61865:
> > +    A memory leak in the hough lines operation: when a specific operation 
> > fails,
> > +    a small memory leak occurs.
> > +  * Fix CVE-2026-61866:
> > +    A memory leak vulnerability in the JNG encoder when a blob cannot be 
> > opened.
> > +  * Fix CVE-2026-61887:
> > +    A memory leak vulnerability in the TIFF encoder when memory allocation 
> > fails.
> 
> I believe this one should be CVE-2026-61867.

Yes fixed thank
> 
> Regards,
> Salvatore
> 

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to