[CLSA-2026:1780661920] ImageMagick: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-05 12:18:57 UTC
Description:
- CVE-2026-28689: fix path policy TOCTOU symlink race allowing read/write of policy-denied files - CVE-2026-28692: fix heap buffer over-read in MAT decoder caused by 32-bit integer overflow
Updated packages:
  • ImageMagick-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:3fa04f2d1f2475cc6a23974f0accb7345e6edd706f076f3473f3445eb3b5caee
  • ImageMagick-c++-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:e3004ca16e4e74bb57c5e5859045825b58642e6399957df811a09265dea42474
  • ImageMagick-c++-devel-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:b71f9092d496ebfb4a5bd657d6919eb9134e24c441c470a584503ccc78014847
  • ImageMagick-devel-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:deed9fa38d05023da0b48e59df93d5368f71566d41fbdae3a40f83e398ea6c07
  • ImageMagick-djvu-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:0fd0966ad7b6a9964377c499c4aea4be9ce8a2d7c25ee76f4d228a645e4c51f5
  • ImageMagick-doc-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:78de77e944d0b03031c767ba09f0ded8fdb68d53624139f79638f20f6e4795ee
  • ImageMagick-libs-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:e17e12df78fc8c0f434e3f33bc43f2345e7577aac29e5aed9286dbd9fe986352
  • ImageMagick-perl-6.9.13.25-1.el8.tuxcare.els31.x86_64.rpm
    sha:7c3d9aadd04bb7fc3209f488b7e70357338d50444f9bed3fff5e804abc30c42f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.