USN-8739-1: ImageMagick vulnerabilities
Canonical released USN-8739-1 fixing five ImageMagick flaws that could cause denial of service or arbitrary code execution.
Ubuntu security notice USN-8739-1 patches five ImageMagick vulnerabilities: CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, and CVE-2026-56373 allow denial of service via crafted images on Ubuntu 14.04 through 22.04 LTS. CVE-2026-56370 affects Ubuntu 22.04 LTS and 26.04 LTS and could allow denial of service or arbitrary code execution. Users should apply the updated ImageMagick packages to affected releases.
- Five ImageMagick CVEs fixed, including CVE-2026-56370 allowing arbitrary code execution
- DoS-only flaws affect Ubuntu 14.04 LTS through 22.04 LTS
- Code execution flaw affects Ubuntu 22.04 LTS and 26.04 LTS
- Patches available through Ubuntu package updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56373 +1 in the same advisory: …56366 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory. NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2026-56368 +1 in the same advisory: …56370 | ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service. NVD description · AI analysis pending | 6.3 group max | <1% |
| — | ||
| CVE-2026-56371 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. NVD description · AI analysis pending | 6.9 | <1% |
| — |
It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, CVE-2026-56373) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-56370) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause…
This source does not provide full text. Read it at ubuntu.com.