Release date:
2026-09-15 10:13:00 UTC
Description:
- Rebase to EPEL 8 ImageMagick-6.9.13.52-2.el8, picking up the vendor's
upstream soname-revert patch
- Drop the TuxCare backports for CVE-2026-61857, CVE-2026-61861,
CVE-2026-61863, CVE-2026-61866 and CVE-2026-61870: all five are fixed in the
6.9.13.52 tarball, verified against the extracted source rather than the
changelog
- Keep the CVE-2026-45664 backport: upstream dd198f960 landed in ImageMagick 7
and never reached the 6.x line, so both MNG_MAX_LOOP_OPS abort paths in
coders/png.c still leak the chunk buffer here
- Keep the MSL empty-image crash fix (partial backport of upstream fde1f305,
not present in the legacy 6.x line)
- CVE-2026-86420: relinquish the MemoryResource reservation when the
in-memory pixel-cache allocation fails in OpenPixelCache (magick/cache.c)
- CVE-2026-86421: destroy the level's draw_info when MSLEndElement pops a
group (coders/msl.c) to prevent a memory leak
Updated packages:
-
ImageMagick-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:fa6469a136cbc3625592be729e09f91763bb8689bf568cade13fe81e3e508339
-
ImageMagick-c++-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:6ca09097e89f9b3ba141bdda05423b28fd656d5439c7819affce092987412425
-
ImageMagick-c++-devel-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:e6165894f39163bb43e063841e4eb9a6cc9c41a3709b4637c2043b3a58f4514c
-
ImageMagick-devel-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:a3190d6c7be7899b97cb33801d73cd2842b3b2291f9dd2b912a01f1a30f1abec
-
ImageMagick-djvu-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:bf13c67d3fb87e8d7da8d35447aef722c41b2a255c19865d9ead1d816c00e969
-
ImageMagick-doc-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:5c87b1b7efd727493bc3d7aa70e25077bba966a5b286b6d02a5a34c069d80948
-
ImageMagick-libs-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:9e6d6151f641b92136421f1027248d77bd2f644c6763103ce31fe29009995f3d
-
ImageMagick-perl-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:9740f104f7482302072628a8d5ca8d2bae1d6d96fa8975f6945fbd27aec0747c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.