[CLSA-2026:1780662070] ImageMagick: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-05 12:21:36 UTC
Description:
- CVE-2026-28689: fix path policy TOCTOU symlink race allowing read/write of policy-denied files - CVE-2026-28692: fix heap buffer over-read in MAT decoder caused by 32-bit integer overflow
Updated packages:
  • ImageMagick-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:240d302cc6f007e54bee66bcfe05cd316d951ac97568d86019a6bfee29cf8b01
  • ImageMagick-c++-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:559d7c6eb56f33b3656e43fe6b0ce45ea84ede5c1439b5d62c3cd9feb29d321c
  • ImageMagick-c++-devel-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:2ea782a2f5b2ffdceb914408b93c9c407e306f6ab87065582b8d0cef359239c4
  • ImageMagick-devel-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:0229d53d5d905b3616d26579410a69f3c35cc52efd2b85068dbdc6d16db710dc
  • ImageMagick-djvu-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:7f4f07236cab2440b7871aa0d39276fca74cf4037152218a87a25057045958a4
  • ImageMagick-doc-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:f89cfb613369db00446f11b43dcc98e1c16c9b1c3ad610ff25c2be441b3d7fd6
  • ImageMagick-libs-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:b99280581123826308919f9d77480352e33f0b4172b070d65ea8eaaab71b9148
  • ImageMagick-perl-6.9.13.25-1.el8_5.tuxcare.els31.x86_64.rpm
    sha:72c29b34ded877448f184d914f521f12361c53e404e97bb8f3d9910f4d840b5a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.