FEDORA-EPEL-2026-bc7538a3d7
Packages in this update:
- ImageMagick-6.9.13.50-1.el8
Update description:
Update to 6.9.13.50
Summary
This update fixes several security vulnerabilities, including multiple
high-severity CVEs:
Security fixes
- CVE-2026-33901 (High) — Heap buffer overflow in the MVG decoder that
could result in an out-of-bounds write when processing a crafted image.
- CVE-2026-33908 (High) — Recursive DestroyXMLTree() call with no depth
limit causes stack exhaustion when processing deeply nested XML structures,
resulting in a Denial of Service (DoS).
- CVE-2026-40310 (High) — Heap out-of-bounds write in the JP2 encoder
triggered when a user specifies an invalid sampling index.
Additional security and bug fixes are included in the upstream releases
between 6.9.13.25 and 6.9.13.49. See the upstream release history at:
https://github.com/ImageMagick/ImageMagick6/releases