[CLSA-2026:1784536924] ImageMagick: Fix of 17 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-20 08:43:03 UTC
Description:
- Rebase to upstream 6.9.13.50, matching EPEL 8 ImageMagick-6.9.13.50-1.el8 - Drop the TuxCare CVE patches whose fixes are included in the upstream 6.9.13.50 release - Keep the MSL empty-image crash fix (partial backport of upstream fde1f305, not present in the legacy 6.x line) - CVE-2026-45664: free the chunk buffer on the MNG LOOP/ENDL op-cap abort path (upstream dd198f960, not yet included in 6.9.13.50) to prevent a heap memory leak when the loop-operation limit is hit
Updated packages:
  • ImageMagick-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:77db17aab026d3a5984312351550e13391c4b3dd5fa2e72597a52c41ae9d335d
  • ImageMagick-c++-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:18d4d9ecf19891aba2732f7c4350954f700dfcf41a0358efdc333f92e7ae78e5
  • ImageMagick-c++-devel-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:1e6b7d176e79506447416d40f84cb47b72f51c8d1873d2528410207f2b0b57a9
  • ImageMagick-devel-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:a5c105b5364e4ea98ca01769abead0418c199c02d0836e54e149236ac1b8c584
  • ImageMagick-djvu-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:da3914da98170b63a81dc006fe5afd58f9c4d94db29c3038526d3b0cf4533c01
  • ImageMagick-doc-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:2b0909526bc99d6bc24a50e457470943ed8a23d5cf89e186602fb81dd00e70f9
  • ImageMagick-libs-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:581265854545b5adef4168dac56761841f104c2754e0df6a22d524b63de55104
  • ImageMagick-perl-6.9.13.50-1.el8_4.tuxcare.els1.x86_64.rpm
    sha:1c1c9f19afd9521b9aaf043d7198cedd2785b49ad4c54b1a80b06fd93942d9ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.