SB20261001147 - Ubuntu update for imagemagick



SB20261001147 - Ubuntu update for imagemagick

Published: October 1, 2026

Security Bulletin ID SB20261001147
CSH Severity
High
Patch available
YES
Number of vulnerabilities 15
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Medium 33% Low 53%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 15 vulnerabilities.


1) Memory leak (CVE-ID: CVE-2026-56366)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in the META reader when processing the APP1JPEG input path. A remote attacker can force the application to leak memory and perform denial of service attack.


2) Memory leak (CVE-ID: CVE-2026-56368)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in multiple coders that write raw pixel data. A remote attacker can force the application to leak memory and perform denial of service attack.


3) Memory leak (CVE-ID: CVE-2026-56371)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in coders/txt.c without freetype. A remote attacker can force the application to leak memory and perform denial of service attack.


4) Use-after-free (CVE-ID: CVE-2026-56373)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the PDB decoder. A remote attacker can perform a denial of service (DoS) attack.


5) Out-of-bounds write (CVE-ID: CVE-2026-56370)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in ConnectedComponentsImage() when processing an invalid index in CLI-controlled connected-components:* artifacts. A remote attacker can supply a specially crafted define value to cause a denial of service.

User interaction is required to process the crafted input.


6) Out-of-bounds read (CVE-ID: CVE-2026-56378)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in the PCD coder’s DecodeImage loop. A remote attacker can trigger an out-of-bounds read error and read contents of memory on the system.


7) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-56379)

CWE-ID: CWE-116 - Improper Encoding or Escaping of Output

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands on the system.

The vulnerability exists due to improper encoding or escaping of output within coders/svg.c. A remote attacker can pass specially crafted data to the application and execute arbitrary commands.


8) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-61465)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in matrix-backed operations when processing crafted image content. A remote attacker can trigger matrix-based operations such as -canny to cause a denial of service.

User interaction is required to process the crafted image content.


9) Use-after-free (CVE-ID: CVE-2026-61857)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in the XMP profile parser when parsing an XMP profile. A remote attacker can supply a crafted XMP profile to cause a denial of service.


10) Memory leak (CVE-ID: CVE-2026-61863)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the TIFF encoder when a temporary file cannot be created. A remote attacker can trigger creation of a temporary file failure to cause a denial of service.


11) Memory leak (CVE-ID: CVE-2026-61864)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the color transformation to log colorspace operation when transforming an image to the log colorspace and the operation fails. A remote attacker can trigger a failed image transformation to cause a denial of service.


12) Memory leak (CVE-ID: CVE-2026-61865)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the hough lines operation when a specific operation fails. A remote attacker can trigger a failure condition to cause a denial of service.


13) Memory leak (CVE-ID: CVE-2026-61870)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the VIFF encoder when handling allocation failures. A remote attacker can trigger an allocation failure to cause a denial of service.


14) Memory leak (CVE-ID: CVE-2026-61866)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the JNG encoder when opening a blob during JNG file encoding. A remote attacker can trigger a blob open failure to cause a denial of service.


15) Integer overflow (CVE-ID: CVE-2026-62946)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to integer overflow in the JNX decoder when parsing an extremely large JNX file on 32-bit builds. A remote attacker can supply a specially crafted JNX file to cause a denial of service or execute arbitrary code.

Only 32-bit builds are vulnerable.


Remediation

Install update from vendor's website.