[CLSA-2026:1780660156] ImageMagick: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-05 11:50:54 UTC
Description:
- CVE-2026-28689: fix path policy TOCTOU symlink race allowing read/write of policy-denied files - CVE-2026-28692: fix heap buffer over-read in MAT decoder caused by 32-bit integer overflow
Updated packages:
  • ImageMagick-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:2c5189e9d81d215723b30851427b96687c4c37f324529da7a4b15aa8c8116d01
  • ImageMagick-c++-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:a85ded4160585021c8cd822ad9c356658883d4e38a1a70ed978897df5325dbe7
  • ImageMagick-c++-devel-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:923cf85ecfd60551bd99d8e4c10e01fc0eb75bcc81a4a447dcf7339cc4b5efad
  • ImageMagick-devel-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:0f174be32410f04bcc774c57e512f52b0f027f99cfea5b8f4595415d291e127e
  • ImageMagick-djvu-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:d32f7bd6096aed366cf8180ab863d3b35f2ea1543cf377ece6acd568bd247c42
  • ImageMagick-doc-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:f66c59ddba33138e0a1a75a65f17cefd065cf91bc2e9aa0d2a5b2e61a86c8727
  • ImageMagick-libs-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:a859bd69f4430d1d9312b12efe3e73f33b73ac3225fe58bc78c0fca46b5d9171
  • ImageMagick-perl-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:8bc2fe8702424133d1c1b55adcc1c6f0ca09cc9d818fd822a261563866d05b47
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.