Bastien Roucariès pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
412897e3 by Bastien Roucariès at 2026-07-22T16:18:37+02:00
Imagemagick/triagging

Some fix are on jumbo patch

- - - - -
d86256f9 by Bastien Roucariès at 2026-07-22T16:37:35+02:00
CVE-2026-61867/imagemagick

This is an im7 only bug:
- according to cve report
- by code analysis
- by introducing commit

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -8013,8 +8013,11 @@ CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x 
before 6.9.13-51 contains
 CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak 
vulnerability in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)
+       [bookworm] - imagemagick <not-affected> (vulnerable code introduced 
later)
+       [bullseye] - imagemagick <not-affected> (vulnerable code introduced 
later)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/f34065ecd9512df16cb10083c8b4b46b5cd09b30
 (7.1.2-26)
+       NOTE: Introduced by 
https://github.com/ImageMagick/ImageMagick/commit/14c08dcd1910ecd8360f51d13885b2c9c39b655d
 (7.0.1-0)
 CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak 
vulnerability in th ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)
@@ -8026,25 +8029,29 @@ CVE-2026-61865 (ImageMagick before 7.1.2-26 and 
6.9.13-51 contains a memory leak
        [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4
 (7.1.2-26)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
 (6.9.13-52)
+       NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, 
CVE-2026-61864, CVE-2026-61863
 CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory 
leak in co ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a
 (7.1.2-26)
+       NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
 (6.9.13-52)
+       NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, 
CVE-2026-61861, CVE-2026-61865
 CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) 
contains a memo ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
 (6.9.13-52)
-       NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862
+       NOTE: For imagemagick 6 patch include fix fro CVE-2026-61862, 
CVE-2026-61864, CVE-2026-61865
 CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an 
information disc ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6
 (7.1.2-26)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8
 (6.9.13-52)
-       NOTE: For imagemagick 6 patch include fix fro CVE-2026-61863
+       NOTE: For imagemagick 6 patch include fix for CVE-2026-61863, 
CVE-2026-61864
 CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a 
use-after-free vu ...)
        - imagemagick 8:7.1.2.26+dfsg1-1
        [trixie] - imagemagick <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bd8f4a533604617afe3267a1ec93893716ecf2fa...d86256f991d0c27a0181f18eeb706514da1f7d15

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bd8f4a533604617afe3267a1ec93893716ecf2fa...d86256f991d0c27a0181f18eeb706514da1f7d15
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to