-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 12 Jul 2026 10:37:54 +0200 Source: imagemagick Architecture: source Version: 8:6.9.11.60+dfsg-1.6+deb12u12 Distribution: bookworm-security Urgency: high Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: imagemagick (8:6.9.11.60+dfsg-1.6+deb12u12) bookworm-security; urgency=high . * Backport policy from 6.9.13-58 * Fix CVE-2026-53466: An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. * Fix CVE-2026-53467: The MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. * Backport draw.c from 6.9.13-52 * Fix CVE-2026-55577: A heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. * Fix CVE-2026-55594: A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided * Fix CVE-2026-55595 When providing invalid arguments to the connected-components option an infinite loop will occur. * Fix CVE-2026-55597: An incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder * Fix CVE-2026-55628: The `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy * Fix CVE-2026-56361: Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations. * Fix CVE-2026-56363: A division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. * Fix CVE-2026-56365: A memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service. * Fix CVE-2026-56366: A memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion. * Fix CVE-2026-56367: An integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. * Fix CVE-2026-56368: A memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service. * Fix CVE-2026-56370 An out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. * Fix CVE-2026-56371 a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. * Fix CVE-2026-56373: A use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory. * Fix CVE-2026-56376: A heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. * Fix CVE-2026-56377: An incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries. * Fix CVE-2026-56378: A heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte. Checksums-Sha1: aa7a65985d164b375ff1b5a6e8eaa5a4e451b8d0 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz a8c3ef07242db0e4961bf2783f2508a0ce95f26a 364080 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz a1fa42e1e187341ca7735ccb94694203b29ea201 8959 imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo Checksums-Sha256: 4844f37c6b27017735efe4844729ff4263e3756e7b127214859e89008b4db914 5134 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz c1327baa694029b2447ff0cf9124f40dcdc58a518964fa6bcde86f2ae9addbb7 364080 imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz 6fa5fd58c3c20ce6ee1eb11028b840f6bc3dbe04bcf9b28229521b642851980a 8959 imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo Files: fa198e9e5616deb9229504625ebe08d9 5134 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12.dsc 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz c889a4208ac9dfffdecdb48ca351d07e 364080 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12.debian.tar.xz f41d9a3c692bf18c94f65f3659ae7a8f 8959 graphics optional imagemagick_6.9.11.60+dfsg-1.6+deb12u12_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmpUzhUACgkQADoaLapB CF/BPhAAq3UOk+SFkkBQ0NFt/+gBEkj6/lHKhvJfHdDIaF+X9cAsmI0wPu+KLuFK cQFK5GLY4iZ68ttUSwfGvS0VEt0Sde9WRoIOeO5Yj9Bk2wjGIsdGCCsV2GFjrwT9 TaYKa6OepSAuzfl5X0Z2SxmuGCkUhA6aS5b5pBX0ReWEc0gvL7BZsNMlqZ9/a7h5 MUrFjZXzTvdKr2rZ9Ug/ARgQLeANXHAyPPzjJCQ8wuiJnuOCoTHnPRU6spGQxX2d OBHsGu4+tU2wI2rFQd7lxDOvCOA1U6EQq3+Rmtr4OQIc4KdMTw4Z6lEQFxvhRciU 13dg8BsNU8CpXgD8Z59E9S4pDwj0KVGbQpIG5c5tndfhM5tG+lo6ybsxQk1DTQFm eeGYtOcwkF+YFRFkcdAT9YdYb889gD3saWuFK/Lgz+oD9yj9mSgpfqagKHy5ohhz /CwuyTbaAkcda0IIxYc0WehDJG0NLtKdOa8Tu5DzoAdNfcYEAfbb1qyguc7+Qhv1 kbURBhmnQ8DOkBO6LPtlGM+El2pzNOkCRLRb+LfLKn0quKFo09iqCXtf2h2BUiud yu6T7LxrOc4ryyAXgkceYBEbHzVQJLL9APl21Jxv1PAXyR+aO73xEgLb6nKJOT0V cgH+yWdDbQWorIPXomTayE0FfYpEw4y5MQ8J9u7/4KTY4nK5GRY= =qbiA -----END PGP SIGNATURE-----