[CLSA-2026:1780660837] ImageMagick: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-05 12:02:23 UTC
Description:
- CVE-2026-28689: fix path policy TOCTOU symlink race allowing read/write of policy-denied files - CVE-2026-28692: fix heap buffer over-read in MAT decoder caused by 32-bit integer overflow
Updated packages:
  • ImageMagick-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:84215d7fdad6d6260034d62bd0fc84cb29176d419e01f9652f801b9e68aaac78
  • ImageMagick-c++-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:44552161cf08b6aec0896e9318d5827e59ede234f2336d353c46ae556e0c173d
  • ImageMagick-c++-devel-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:a2afe28c28bdd2a602beefcd40abe1ad3b63a548b015c92f13ddb64e261b126b
  • ImageMagick-devel-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:d0f4dac303bbd85f7f9c52b8f69f8bae8ca418a4b817a8ea7ba2a541321c8b94
  • ImageMagick-djvu-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:c15736ef00a8ea2d90b8a5f81221209a6d93d4702c362bc21e908c15dd1099fa
  • ImageMagick-doc-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:374d8e8a76704599e59d2b1fba30c669c5b1d134972823bc57a20b56a21272de
  • ImageMagick-libs-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:2c80bc864f857f6f3916574e91cc1f344efed84601f329c218d9f686710484f6
  • ImageMagick-perl-6.9.13.25-1.el8_4.tuxcare.els31.x86_64.rpm
    sha:5cbbc73c7f031c7efcc23fee2efcb1abbca5006422f0c9c4d4b83671297a0a34
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.