[CLSA-2026:1784537825] ImageMagick: Fix of 17 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-20 08:58:05 UTC
Description:
- Rebase to upstream 6.9.13.50, matching EPEL 8 ImageMagick-6.9.13.50-1.el8 - Drop the TuxCare CVE patches whose fixes are included in the upstream 6.9.13.50 release - Keep the MSL empty-image crash fix (partial backport of upstream fde1f305, not present in the legacy 6.x line) - CVE-2026-45664: free the chunk buffer on the MNG LOOP/ENDL op-cap abort path (upstream dd198f960, not yet included in 6.9.13.50) to prevent a heap memory leak when the loop-operation limit is hit
Updated packages:
  • ImageMagick-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:cda605abc35018d42d365245655210c4128e21dfff1a9e807fd4d3907c9643b5
  • ImageMagick-c++-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:7feb396fe608493464bf78e94378cb2438d38fc0c13c3913c5f734b0ae41904d
  • ImageMagick-c++-devel-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:5559a6cf9959cc36dcfee1025cb928f5f0f2b0dcaa6c1f8cb74e495086d49e5c
  • ImageMagick-devel-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:3188eeacc7253022650a55ea670abbdad833399da6219ad9466f214c60ca064d
  • ImageMagick-djvu-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:438b348bb3fb247c308ac54274d3388c531d65b666f3c9ded4f906b5fb91fce5
  • ImageMagick-doc-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:fe7909a4ae1f313eebb759f76d9ca0a33948698b562e1f3bb2fd82038a223401
  • ImageMagick-libs-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:0ad69abb42874cc91a2f3bb8a600cbaf1eccd7253b763d1392bb999956ee52e3
  • ImageMagick-perl-6.9.13.50-1.el8_5.tuxcare.els1.x86_64.rpm
    sha:a799e5688d4f6e695bfa9c0f16980928d99233f8ea2a14eb405d98bde127ca25
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.