Advisories ยป MGASA-2026-0414

Updated imagemagick package fixes security vulnerabilities

Publication date: 17 Sep 2026
Modification date: 17 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-86420 , CVE-2026-86421 , CVE-2026-86423 , CVE-2026-86424 , CVE-2026-86425

Description

Heap-use-after-free in Layer method of PerlMagick could result in a
crash
Path Policy TOCTOU symlink race bypass in the video decoder
Heap-use-after-free in the GetList method of PerlMagick could result in
a crash
Memory Leak in MSL decoder
Denial of service when exhausting the process memory budget
Policy Bypass in UHDR encoder
Division by Zero in FLIF encoder
Null Pointer Dereference in PNM coder when hitting a memory limit
Policy Bypass in PCD, CUBE and HALD decoder when using a specific
command line option.
Use after free in ImagesToBlob method
                

References

SRPMS

10/core

10/tainted