-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Jul 2026 23:08:38 +0200 Source: imagemagick Architecture: source Version: 8:6.9.11.60+dfsg-1.3+deb11u16 Distribution: bullseye-security Urgency: high Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: imagemagick (8:6.9.11.60+dfsg-1.3+deb11u16) bullseye-security; urgency=high . * Fix CVE-2026-61464: A heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title * Fix CVE-2026-61465: A missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. * Fix CVE-2026-61857: A heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. * Fix CVE-2026-61858: A policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. * Fix CVE-2026-61859: Policy bypass vulnerability in the -script operation due to missing security policy checks. * Fix CVE-2026-61860: A use-after-free vulnerability that occurs when freetype initialization fails. * Fix CVE-2026-61862: When a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). * Fix CVE-2026-61863: A memory leak in the TIFF encoder that occurs when a temporary file cannot be created, * Fix CVE-2026-61864: A memory leak in color transformation to the log colorspace. * Fix CVE-2026-61865 A memory leak in the hough lines operation. * Fix CVE-2026-61866: A memory leak vulnerability in the JNG encoder when a blob cannot be opened. * Fix CVE-2026-61868: A memory leak in the YUV decoder that occurs when opening of the blob fails * Fix CVE-2026-61869: A memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service. * Fix CVE-2026-61870: A memory leak vulnerability in the VIFF encoder when memory allocation fails. * Fix CVE-2026-61872: memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Checksums-Sha1: 2f1a5b49ecaf431cc453ad587196d5b07f0e3bf0 5232 imagemagick_6.9.11.60+dfsg-1.3+deb11u16.dsc 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz 6a11d98dc8773eb8964bb382405774d370ce0020 368804 imagemagick_6.9.11.60+dfsg-1.3+deb11u16.debian.tar.xz bf421b10ab0acc1fe6398570f1ba9768e6fa2115 9022 imagemagick_6.9.11.60+dfsg-1.3+deb11u16_source.buildinfo Checksums-Sha256: dc7c11f45952000254b4fd68edb0f953aa8fff62f4cd9d65473cf4d2e06403c2 5232 imagemagick_6.9.11.60+dfsg-1.3+deb11u16.dsc 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz 67d5f3d1eddfbd170e064c798382531f8df77ec4443ae8a93384ba24e0095d43 368804 imagemagick_6.9.11.60+dfsg-1.3+deb11u16.debian.tar.xz 7b90482d140919f7e50641f0d0b1535e1b3757140c3154d55b743f370f21db22 9022 imagemagick_6.9.11.60+dfsg-1.3+deb11u16_source.buildinfo Files: ff21139a46545a3dd01f9e7faf93657f 5232 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u16.dsc 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz 1450aea5edc554c39d9e05d04c6cd1cb 368804 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u16.debian.tar.xz ad08c6a8061d31ff01fe1ec69480fa39 9022 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u16_source.buildinfo -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJqYRxpCRAAOhotqkEIX0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmdi9ZpeIt89kumHRTW8ST4SbmQ4HY4MgJaAY3tQLt30 xhYhBF0Bh7lAokW617D1agA6Gi2qQQhfAADRRw/+OMSR+1a7VLJ0RsQqbrGDElyL EdNVczlxlb4Lor+u6nYA6NHd+WXwAchNtqo0QGe6KgwSDYBGb/IGirgQDOWBAHZI w9VJ6cBAh4vshlKOCXGBbdmKWpz0cU+8O+adI0nYl2qwLdiNcFhqU1DTB0MDtlIP PnTKKRsFvzdhRgbFDZRsscz3hYx7SoP/gO4LkwBbbWJwhPvUWWZbqNlN7y5O4kss c0uLpXbm4OTvOvtIkiw3yo1UvEPUC9qH1+9bcUxcizHqDzRTynFjV1bWCmIhuxJx w4kzbhxfRyklS9Oj8E8e6ToEIgtpWBf6mrKufk3i+pC+Pk4DHCNziy7hLtqJrLAi y1TjkmdIAKAzhqKwHefNidrXXJUwsrHuI8g5HrejeBqox1PeQea1hw3ltVF6MndX kfUM6f4VxNKs00to3pc4IIV2lwxjfqJrS7fBsOCAAcroSQqqQbda8ofZrFvfP9GG iB321KUZ1BCjUv11/lE+ONr1K3CRdDsJhAVKnprtMaF5QnxYN7fZK9uTpioOLw1u CYrR84stUbMvUkKjEkUm+76JoryNIth4IBZdegGPgFcXb39/vf1fYqmKN7znivaH orpp4uvAOrAZRkk4ez0EXoZJRAdjmYWuMnD/chpgEnbyMF9NDvY6LO0xZ6mpzG1U r6YK2GzSOl2g7Ff1Edw= =Hcqr -----END PGP SIGNATURE-----