Release date:
2026-09-15 10:17:10 UTC
Description:
- Rebase to EPEL 8 ImageMagick-6.9.13.52-2.el8, picking up the vendor's
upstream soname-revert patch
- Drop the TuxCare backports for CVE-2026-61857, CVE-2026-61861,
CVE-2026-61863, CVE-2026-61866 and CVE-2026-61870: all five are fixed in the
6.9.13.52 tarball, verified against the extracted source rather than the
changelog
- Keep the CVE-2026-45664 backport: upstream dd198f960 landed in ImageMagick 7
and never reached the 6.x line, so both MNG_MAX_LOOP_OPS abort paths in
coders/png.c still leak the chunk buffer here
- Keep the MSL empty-image crash fix (partial backport of upstream fde1f305,
not present in the legacy 6.x line)
- CVE-2026-86420: relinquish the MemoryResource reservation when the
in-memory pixel-cache allocation fails in OpenPixelCache (magick/cache.c)
- CVE-2026-86421: destroy the level's draw_info when MSLEndElement pops a
group (coders/msl.c) to prevent a memory leak
Updated packages:
-
ImageMagick-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:21300f7bbf56508af9758cec7cd7fbb699ebff3bff34d3f41bcaa398bb955deb
-
ImageMagick-c++-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:2e196aaff44269fb724e369b28e8f57a1f6ca35192e5d78605310a4a0b5579b2
-
ImageMagick-c++-devel-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:03be15b7d1bba2cb0a99c9064edca965bad4fcb89ad780388f381d59ad49c6a1
-
ImageMagick-devel-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:22e63d71f561c379c87b5fee4a29da94b3589f8e7cfa5f583cc283f02c3b0ee3
-
ImageMagick-djvu-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:5f9dd08934e4415d80bdff7404e1bda9250b102bedc517357939fc398ed4f3e7
-
ImageMagick-doc-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:33322a43908b07a185d52c8535af7043c3f07fc76ec3c47516528a85a089cf39
-
ImageMagick-libs-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:6ea34975cfbccf28deddc807ae48062c54f8a8c1846a08d5387cad9b9baa6395
-
ImageMagick-perl-6.9.13.52-2.el8.tuxcare.els1.x86_64.rpm
sha:5d5982db12b89d61b0376c6116177af9adb89d946edd06a51e05c9023aebed64
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.