-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Jul 2026 09:55:59 +0200 Source: imagemagick Architecture: source Version: 8:7.1.1.43+dfsg1-1+deb13u12 Distribution: trixie Urgency: medium Maintainer: ImageMagick Packaging Team Changed-By: Bastien Roucariès Changes: imagemagick (8:7.1.1.43+dfsg1-1+deb13u12) trixie; urgency=medium . * Fix CVE-2026-56362: A heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex. * Fix CVE-2026-56366: A memory leak vulnerability in the META reader when processing APP1JPEG input paths. * Fix CVE-2026-56372: A heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. * Fix CVE-2026-56373: A use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. * Fix CVE-2026-56374: A heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. * Fix CVE-2026-56375: A memory leak vulnerability in the ASHLAR coder when an action fails * Fix CVE-2026-61464: A heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title. * Fix CVE-2026-61465: A missing a check was found, for the allowed memory allocation limit in matrix-backed operations such as -canny. * Fix CVE-2026-61857: A heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. * Fix CVE-2026-61858: A policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. * Fix CVE-2026-61859: A policy bypass vulnerability in the -script operation due to missing security policy checks. * Fix CVE-2026-61860: a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. * Fix CVE-2026-61861: A use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. * Fix CVE-2026-61862: When a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed. * Fix CVE-2026-61863: A memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. * Fix CVE-2026-61864: A memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. * Fix CVE-2026-61865: A memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. * Fix CVE-2026-61866: A memory leak vulnerability in the JNG encoder when a blob cannot be opened. * Fix CVE-2026-61867: A memory leak vulnerability in the TIFF encoder when memory allocation fails. * Fix CVE-2026-61868: a memory leak in the YUV decoder that occurs when opening of the blob fails. * Fix CVE-2026-61869: A memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing. * Fix CVE-2026-61870: A memory leak vulnerability in the VIFF encoder when memory allocation fails. * Fix CVE-2026-61871: A memory leak in the ICON decoder that occurs when a memory allocation fails. * Fix CVE-2026-61872: a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Checksums-Sha1: 5b646841a7a4f3ec8617e000913203f9c26b6977 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc 103af0af388a733c043845b228cf3031c16d859b 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz f113f2657e3f88fcea4c22927316053cf595fd60 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz 3f0b7d64c26d9044c613beb93523e2bd5f8e35e7 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo Checksums-Sha256: d82041b1f5888ca181eeb4316981c31ae9d9c54060f1f4ec10a2d23dd80c8aeb 5263 imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc bcb4f3c78a930a608fa4889f889edbcb384974246ad9407fce1858f2c0607bfe 10501740 imagemagick_7.1.1.43+dfsg1.orig.tar.xz 4ab5e32a172da4a244afa140570d1c48fd48d5c7a64dfce6704917f30081c9f3 366728 imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz d96f4c803f8caa151ba791817d9f1a3cc551aa3aad4c5e606d2fc70c63a8ce0b 8935 imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo Files: dd2d3dcebca275f2cc20be646e49953d 5263 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.dsc 01cfb13a7c1813afb50790e431358c6c 10501740 graphics optional imagemagick_7.1.1.43+dfsg1.orig.tar.xz 83899433bcf397389cbd017d3517492b 366728 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12.debian.tar.xz 7b3b28f766199c8a7dff292caf2e6616 8935 graphics optional imagemagick_7.1.1.43+dfsg1-1+deb13u12_source.buildinfo -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJqcu8ACRAAOhotqkEIX0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmc0rkoyWYM3Th4M/pe94DJUFQ5DCyAlqavU1xS89sMW ZRYhBF0Bh7lAokW617D1agA6Gi2qQQhfAAA3sA//V5ydzV6r4T+k8V7FMMJ9CFCA WG9T7t0vhtCWNfNRy2Vbqs/yJmcsdPfTipV81+6gEBW63Pyco1kRNf6GNnE90X7k hS1cmWzxJtbmHrR3DR6pHOrZj1BYS7Ow/3jKzStqnHWHkj4xy+BFMaWnBDaA8s/U qwC86Ve7fUR8YeZLRYH74L1E1pXoM/5awFsIWxCpqnbU/yTkgaScg8nYZ7e4qPP4 4UFHYGITpgaLwhTwLJwn/BmGqP/zFo7HDMr1CJMRx6EmNzjlOo5WwFPRMeUme2+B 769JsOxjtmPqxTED2o0huLzlTJCE+tlSbuD5FLz4WpICb/VLgCSSU8eWApEtIUkE 9QabH9Hz6G99jEz1qmroPLF2wsRpWbJYg7HryqJlzasgn2v9NX5imVIgOblBgKzQ WYjJTk1iZzPqG1mPXvD7vBfqhZSlpixepVDx7MEakcIsx47xdPEBbNp2Kl1DxMhg b7jMyZ0RmAab/i07M/8oec4A/heZYMvFHMsjzEYRr2QoU6WAPMBdUSZXMp7nyeJw QFNQAOQBLQzxzoFCikU/7e5Ha/JeBdU4vPTGgc0rVFWWFNj07ehxNBCE//YunIfe h4VxaNP36rmiJwGTxCyWHhQzlY1Rl7aZaX8KcuGEAP9mUck9Ke51MtfgthOV5Z76 KmZ57dWz+Usf9wNfUC0= =MKhs -----END PGP SIGNATURE-----