Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8127-1: ImageMagick vulnerabilities

  • What: Multiple vulnerabilities in ImageMagick.
  • Impact: Could lead to denial of service attacks.
Read Full Article →

It was discovered that ImageMagick did not properly process certain tags prior to an image being loaded. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. (CVE-2026-23952) It was discovered that ImageMagick did not properly handle temporary file creation failures. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795) It was discovered that ImageMagick did not properly manage memory under certain conditions. An attacker could possibly use this issue to cause ImageMagick to consume resources, resulting in a denial of service. (CVE-2026-25796) It was discovered that ImageMagick incorrectly handled certain specially crafted image files. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. (CVE-2026-25798) It was discovered that ImageMagick did not properly validate certain YUV sampling factors. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. (CVE-2026-25799) It was discovered that ImageMagick incorrectly handled certain specially crafted image files. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-25970) It was discovered that ImageMagick incorrectly managed memory when handling certain specially crafted image files. An attacker could possibly use this issue to cause ImageMagick to consume resources, resulting in a denial of service. (CVE-2026-25988) It was discovered that ImageMagick incorrectly handled certain crafted image profiles. An attacker could possibly use this issue to cause ImageMagick to consume available resources, resulting in a denial of service. (CVE-2026-26066) It was discovered that ImageMagick incorrectly handled large image profiles when encoding PNG images. An attacker could use this issue to cause ImageMagick to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-30883) Kamil Frankowicz discovered that ImageMagick incorrectly handled certain XML data. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service. (CVE-2026-32636)

Share this article