Aggregator

USN-8592-1: ImageMagick vulnerabilities

4 hours 16 minutes ago
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-30936) It was discovered that ImageMagick incorrectly handled extremely large XWD images. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. (CVE-2026-30937) It was discovered that ImageMagick incorrectly handled extremely large SFW images on 32-bit systems. An attacker could possibly use this issue to trigger an integer overflow, resulting in a denial of service. (CVE-2026-31853) It was discovered that ImageMagick incorrectly handled memory allocation failures in the sixel encoder. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-32259)

GraphicsMagick-1.3.45-10.fc45 ImageMagick-7.1.2.29-2.fc45 OpenImageIO-3.1.15.0-4.fc45 OpenImageIO2.5-2.5.19.1-17.fc45 darktable-5.4.1-12.fc45 digikam-9.1.0-3.fc45 ffmpeg-8.1.2-10.fc45 geeqie-2.7-6.fc45 gimp-3.2.4-4.fc45 gthumb-4.0~beta-4.fc45 imlib2-1.12…

7 hours ago
FEDORA-2026-26ae66c60f Packages in this update:
  • darktable-5.4.1-12.fc45
  • digikam-9.1.0-3.fc45
  • ffmpeg-8.1.2-10.fc45
  • geeqie-2.7-6.fc45
  • gimp-3.2.4-4.fc45
  • GraphicsMagick-1.3.45-10.fc45
  • gthumb-4.0~beta-4.fc45
  • ImageMagick-7.1.2.29-2.fc45
  • imlib2-1.12.5-4.fc45
  • imv-5.0.1-4.fc45
  • kf5-kimageformats-5.116.0-12.fc45
  • kf6-kimageformats-6.29.0-2.fc45
  • libheif-1.23.1-9.fc45
  • mingw-openexr-3.4.13-3.fc45
  • mpv-0.41.0-8.fc45
  • openapv-0.3.0.0-1.fc45
  • OpenImageIO2.5-2.5.19.1-17.fc45
  • OpenImageIO-3.1.15.0-4.fc45
  • openjph-0.31.0-1.fc45
  • perl-Prima-1.77-6.fc45
  • python-imagecodecs-2025.8.2-7.fc45
  • siril-1.4.4-3.fc45
  • swayimg-5.5-2.fc45
  • vapoursynth-79-3.fc45
  • vips-8.18.3-4.fc45
  • xevd-0.7.0-2.fc45
  • xeve-0.7.0-2.fc45
Update description:

Updated xeve/xevd, updated openapv and updated vapoursynth.

USN-8626-1: systemd vulnerabilities

10 hours 35 minutes ago
It was discovered that systemd-homed did not properly verify the signature of home records. A local attacker could possibly use this issue to add arbitrary system groups to a logged-in user and gain elevated privileges. (CVE-2026-16742) It was discovered that systemd-machined incorrectly handled certain polkit authorization checks. A local attacker could possibly use this issue to terminate arbitrary processes, including privileged ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15060) It was discovered that systemd-oomd did not properly validate certain IPC requests. A local attacker could possibly use this issue to terminate arbitrary processes. (CVE-2026-15059)

libcupsfilters-2.2.0-1.fc45

12 hours 57 minutes ago
FEDORA-2026-4acc8aafb3 Packages in this update:
  • libcupsfilters-2.2.0-1.fc45
Update description:

Automatic update for libcupsfilters-2.2.0-1.fc45.

Changelog * Thu Aug 6 2026 Zdenek Dohnal <zdohnal@redhat.com> - 1:2.2.0-1 - libcupsfilters-2.2.0 is available (fedora#2511889) * Wed Aug 5 2026 Zdenek Dohnal <zdohnal@redhat.com> - 1:2.1.1-9 - fixes CVE-2026-64611 and CVE-2026-64612 (fedora#2506364)

Automatic update for libcupsfilters-2.1.1-9.fc45.