23 hours 32 minutes ago
Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-30936)
It was discovered that ImageMagick incorrectly handled extremely large
XWD images. An attacker could possibly use this issue to trigger an
out-of-bounds heap write, resulting in arbitrary code execution.
(CVE-2026-30937)
It was discovered that ImageMagick incorrectly handled extremely large
SFW images on 32-bit systems. An attacker could possibly use this issue
to trigger an integer overflow, resulting in a denial of service.
(CVE-2026-31853)
It was discovered that ImageMagick incorrectly handled memory allocation
failures in the sixel encoder. An attacker could possibly use this issue
to trigger a stack buffer overflow, resulting in arbitrary code
execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-32259)