openSUSE 16: ImageMagick / ImageMagick-config-7-SUSE / etc (openSUSE-SU-2026:21071-1)

medium Nessus Plugin ID 324064

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21071-1 advisory.

This update for ImageMagick fixes the following issues

Security issues:

- CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048).
- CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092).
- CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094).
- CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102).
- CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095).
- CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096).
- CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101).
- CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112).
- CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124).
- CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126).
- CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125).
- CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123).
- CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121).
- CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick
-distribute- cache service (bsc#1268120).
- CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117).
- CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114).
- CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick
-distribute- cache service (bsc#1268113).
- CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering (bsc#1268116).
- CVE-2026-48733: Infinite Loop in subimage-search with crafted image (bsc#1268119).
- CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122).
- CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111).
- CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110).
- CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108).
- CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107).
- CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105).
- CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103).
- CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out- of-bounds read (bsc#1268645).
- CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064).
- CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected- components:* artifacts with invalid indices (bsc#1269063).
- CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879).
- CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880).

Non security issue:

- ImageMagick update 7.1.2.0-160000.9.1 is broken for softlinks (bsc#1265373).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1265048

https://bugzilla.suse.com/1265373

https://bugzilla.suse.com/1268092

https://bugzilla.suse.com/1268094

https://bugzilla.suse.com/1268095

https://bugzilla.suse.com/1268096

https://bugzilla.suse.com/1268101

https://bugzilla.suse.com/1268102

https://bugzilla.suse.com/1268103

https://bugzilla.suse.com/1268105

https://bugzilla.suse.com/1268107

https://bugzilla.suse.com/1268108

https://bugzilla.suse.com/1268110

https://bugzilla.suse.com/1268111

https://bugzilla.suse.com/1268112

https://bugzilla.suse.com/1268113

https://bugzilla.suse.com/1268114

https://bugzilla.suse.com/1268116

https://bugzilla.suse.com/1268117

https://bugzilla.suse.com/1268119

https://bugzilla.suse.com/1268120

https://bugzilla.suse.com/1268121

https://bugzilla.suse.com/1268122

https://bugzilla.suse.com/1268123

https://bugzilla.suse.com/1268124

https://bugzilla.suse.com/1268125

https://bugzilla.suse.com/1268126

https://bugzilla.suse.com/1268645

https://bugzilla.suse.com/1268879

https://bugzilla.suse.com/1268880

https://bugzilla.suse.com/1269063

https://bugzilla.suse.com/1269064

https://www.suse.com/security/cve/CVE-2026-40169

https://www.suse.com/security/cve/CVE-2026-42050

https://www.suse.com/security/cve/CVE-2026-42326

https://www.suse.com/security/cve/CVE-2026-45031

https://www.suse.com/security/cve/CVE-2026-45358

https://www.suse.com/security/cve/CVE-2026-45359

https://www.suse.com/security/cve/CVE-2026-45624

https://www.suse.com/security/cve/CVE-2026-45664

https://www.suse.com/security/cve/CVE-2026-46520

https://www.suse.com/security/cve/CVE-2026-46521

https://www.suse.com/security/cve/CVE-2026-46522

https://www.suse.com/security/cve/CVE-2026-46523

https://www.suse.com/security/cve/CVE-2026-46557

https://www.suse.com/security/cve/CVE-2026-46559

https://www.suse.com/security/cve/CVE-2026-46692

https://www.suse.com/security/cve/CVE-2026-46693

https://www.suse.com/security/cve/CVE-2026-47165

https://www.suse.com/security/cve/CVE-2026-47166

https://www.suse.com/security/cve/CVE-2026-48724

https://www.suse.com/security/cve/CVE-2026-48733

https://www.suse.com/security/cve/CVE-2026-48734

https://www.suse.com/security/cve/CVE-2026-48994

https://www.suse.com/security/cve/CVE-2026-49218

https://www.suse.com/security/cve/CVE-2026-53460

https://www.suse.com/security/cve/CVE-2026-53461

https://www.suse.com/security/cve/CVE-2026-53463

https://www.suse.com/security/cve/CVE-2026-53464

https://www.suse.com/security/cve/CVE-2026-56367

https://www.suse.com/security/cve/CVE-2026-56368

https://www.suse.com/security/cve/CVE-2026-56370

https://www.suse.com/security/cve/CVE-2026-56371

https://www.suse.com/security/cve/CVE-2026-56376

Plugin Details

Severity: Medium

ID: 324064

File Name: openSUSE-2026-21071-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/1/2026

Updated: 7/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.02

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-56367

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 2.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-56376

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:imagemagick-devel, p-cpe:/a:novell:opensuse:imagemagick-extra, p-cpe:/a:novell:opensuse:imagemagick-config-7-upstream-websafe, p-cpe:/a:novell:opensuse:libmagickcore-7_q16hdri10, p-cpe:/a:novell:opensuse:perl-perlmagick, p-cpe:/a:novell:opensuse:imagemagick-config-7-suse, p-cpe:/a:novell:opensuse:imagemagick-config-7-upstream-open, p-cpe:/a:novell:opensuse:libmagick%2b%2b-devel, p-cpe:/a:novell:opensuse:libmagick%2b%2b-7_q16hdri5, p-cpe:/a:novell:opensuse:imagemagick-config-7-upstream-secure, p-cpe:/a:novell:opensuse:libmagickwand-7_q16hdri10, p-cpe:/a:novell:opensuse:imagemagick, p-cpe:/a:novell:opensuse:imagemagick-config-7-upstream-limited

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/26/2026

Vulnerability Publication Date: 2/25/2026

Reference Information

CVE: CVE-2026-40169, CVE-2026-42050, CVE-2026-42326, CVE-2026-45031, CVE-2026-45358, CVE-2026-45359, CVE-2026-45624, CVE-2026-45664, CVE-2026-46520, CVE-2026-46521, CVE-2026-46522, CVE-2026-46523, CVE-2026-46557, CVE-2026-46559, CVE-2026-46692, CVE-2026-46693, CVE-2026-47165, CVE-2026-47166, CVE-2026-48724, CVE-2026-48733, CVE-2026-48734, CVE-2026-48994, CVE-2026-49218, CVE-2026-53460, CVE-2026-53461, CVE-2026-53463, CVE-2026-53464, CVE-2026-56367, CVE-2026-56368, CVE-2026-56370, CVE-2026-56371, CVE-2026-56376