[CLSA-2026:1784537224] ImageMagick: Fix of 18 CVEs
Type:
security
Severity:
Critical
Release date:
2026-07-20 08:48:04 UTC
Description:
- Rebase to upstream 6.9.13.50, matching EPEL 8 ImageMagick-6.9.13.50-1.el8 - Drop the TuxCare CVE patches whose fixes are included in the upstream 6.9.13.50 release - Keep the MSL empty-image crash fix (partial backport of upstream fde1f305, not present in the legacy 6.x line) - CVE-2026-45664: free the chunk buffer on the MNG LOOP/ENDL op-cap abort path (upstream dd198f960, not yet included in 6.9.13.50) to prevent a heap memory leak when the loop-operation limit is hit
Updated packages:
  • ImageMagick-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:3d3c4ecb1e281736269c1615dcb7b97984180e5585127f1c5311980bcee8f2db
  • ImageMagick-c++-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:c589d29bd2f4db2e80e9f94b4ad0932dcb2b7eead9b57495013782452ccfba73
  • ImageMagick-c++-devel-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:76f8d92e84a3b1c7bc142be9aed5f2d9d51a7c77714143c00819b3d7ee39c5c8
  • ImageMagick-devel-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:0cd0f603aa463b3ebe06d21bd635d5b7985fcdf7103261580ed73a2be95b1120
  • ImageMagick-djvu-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:9167670901b84d3b2419726cc33abc1aeea636cd57554e3dce9b47598e50063b
  • ImageMagick-doc-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:82f585b734d167f60570529982ea2126672a1234bbfaff2ec31bf4c835fe19f1
  • ImageMagick-libs-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:2fed888907fb553d6362a1e17705b6dcf8246dc5df6a0c50f4fbc603ff106dbe
  • ImageMagick-perl-6.9.13.50-1.el8.tuxcare.els1.x86_64.rpm
    sha:5541b75df7b0e81a9e6968102fdfe8beb59ef80cdc6276d5dd0b08bb0b11f761
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.