SUSE SLED15 / SLES15 Security Update : ImageMagick (SUSE-SU-2026:3193-1)

medium Nessus Plugin ID 329144

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3193-1 advisory.

This update for ImageMagick fixes the following issues

- CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081).
- CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).
- CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316).
- CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314).
- CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315).
- CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495).
- CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).
- CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496).
- CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313).
- CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312).
- CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311).
- CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497).
- CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294).
- CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493).
- CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492).
- CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491).
- CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490).
- CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489).
- CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488).
- CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487).
- CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486).
- CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293).
- CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-geometry` is specified (bsc#1271484).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected ImageMagick-config-7-upstream package.

See Also

https://bugzilla.suse.com/1268640

https://bugzilla.suse.com/1270006

https://bugzilla.suse.com/1270081

https://bugzilla.suse.com/1271100

https://bugzilla.suse.com/1271293

https://bugzilla.suse.com/1271294

https://bugzilla.suse.com/1271311

https://bugzilla.suse.com/1271312

https://bugzilla.suse.com/1271313

https://bugzilla.suse.com/1271314

https://bugzilla.suse.com/1271315

https://bugzilla.suse.com/1271316

https://bugzilla.suse.com/1271484

https://bugzilla.suse.com/1271486

https://bugzilla.suse.com/1271487

https://bugzilla.suse.com/1271488

https://bugzilla.suse.com/1271489

https://bugzilla.suse.com/1271490

https://bugzilla.suse.com/1271491

https://bugzilla.suse.com/1271492

https://bugzilla.suse.com/1271493

https://bugzilla.suse.com/1271495

https://bugzilla.suse.com/1271496

https://bugzilla.suse.com/1271497

https://www.suse.com/security/cve/CVE-2026-55628

https://www.suse.com/security/cve/CVE-2026-56362

https://www.suse.com/security/cve/CVE-2026-56366

https://www.suse.com/security/cve/CVE-2026-56372

https://www.suse.com/security/cve/CVE-2026-56373

https://www.suse.com/security/cve/CVE-2026-56375

https://www.suse.com/security/cve/CVE-2026-56377

https://www.suse.com/security/cve/CVE-2026-61464

https://www.suse.com/security/cve/CVE-2026-61465

https://www.suse.com/security/cve/CVE-2026-61857

https://www.suse.com/security/cve/CVE-2026-61858

https://www.suse.com/security/cve/CVE-2026-61859

https://www.suse.com/security/cve/CVE-2026-61861

https://www.suse.com/security/cve/CVE-2026-61862

https://www.suse.com/security/cve/CVE-2026-61863

https://www.suse.com/security/cve/CVE-2026-61864

https://www.suse.com/security/cve/CVE-2026-61865

https://www.suse.com/security/cve/CVE-2026-61866

https://www.suse.com/security/cve/CVE-2026-61867

https://www.suse.com/security/cve/CVE-2026-61868

https://www.suse.com/security/cve/CVE-2026-61869

https://www.suse.com/security/cve/CVE-2026-61870

https://www.suse.com/security/cve/CVE-2026-61872

http://www.nessus.org/u?1d5bc6b7

Plugin Details

Severity: Medium

ID: 329144

File Name: suse_SU-2026-3193-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/23/2026

Updated: 7/23/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.74

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-56372

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-61868

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:imagemagick-config-7-upstream

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/22/2026

Vulnerability Publication Date: 6/30/2026

Reference Information

CVE: CVE-2026-55628, CVE-2026-56362, CVE-2026-56366, CVE-2026-56372, CVE-2026-56373, CVE-2026-56375, CVE-2026-56377, CVE-2026-61464, CVE-2026-61465, CVE-2026-61857, CVE-2026-61858, CVE-2026-61859, CVE-2026-61861, CVE-2026-61862, CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61866, CVE-2026-61867, CVE-2026-61868, CVE-2026-61869, CVE-2026-61870, CVE-2026-61872

SuSE: SUSE-SU-2026:3193-1