USN-8592-1: ImageMagick vulnerabilities

Publication date

10 August 2026

Overview

Several security issues were fixed in ImageMagick.


Packages

  • imagemagick - Image manipulation programs and library

Details

Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-30936)

It was discovered that ImageMagick incorrectly handled extremely large
XWD images. An attacker could possibly use this issue to trigger an
out-of-bounds heap write, resulting in arbitrary code execution.
(CVE-2026-30937)

It was discovered that ImageMagick incorrectly handled extremely large
SFW images on 32-bit systems. An attacker could possibly use this issue
to trigger an integer overflow, resulting in a denial of service.
(CVE-2026-31853)

It was...

Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-30936)

It was discovered that ImageMagick incorrectly handled extremely large
XWD images. An attacker could possibly use this issue to trigger an
out-of-bounds heap write, resulting in arbitrary code execution.
(CVE-2026-30937)

It was discovered that ImageMagick incorrectly handled extremely large
SFW images on 32-bit systems. An attacker could possibly use this issue
to trigger an integer overflow, resulting in a denial of service.
(CVE-2026-31853)

It was discovered that ImageMagick incorrectly handled memory allocation
failures in the sixel encoder. An attacker could possibly use this issue
to trigger a stack buffer overflow, resulting in arbitrary code
execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-32259)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble imagemagick –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
imagemagick-6.q16 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
imagemagick-6.q16hdri –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libimage-magick-q16-perl –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libimage-magick-q16hdri-perl –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagick++-6.q16-9t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagick++-6.q16hdri-9t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickcore-6.q16-7-extra –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickcore-6.q16-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickcore-6.q16hdri-7-extra –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickcore-6.q16hdri-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickwand-6.q16-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
libmagickwand-6.q16hdri-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12  
22.04 LTS jammy imagemagick –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
imagemagick-6.q16 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
imagemagick-6.q16hdri –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libimage-magick-q16-perl –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libimage-magick-q16hdri-perl –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagick++-6.q16-8 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagick++-6.q16hdri-8 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickcore-6.q16-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickcore-6.q16-6-extra –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickcore-6.q16hdri-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickcore-6.q16hdri-6-extra –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickwand-6.q16-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
libmagickwand-6.q16hdri-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13  
20.04 LTS focal imagemagick –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libimage-magick-q16-perl –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libimage-magick-q16hdri-perl –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libmagickcore-6.q16-6-extra –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libmagickcore-6.q16hdri-6-extra –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libmagickwand-6.q16-6 –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
libmagickwand-6.q16hdri-6 –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13  
18.04 LTS bionic imagemagick-6.q16 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
imagemagick-6.q16hdri –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libimage-magick-q16-perl –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libimage-magick-q16hdri-perl –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagick++-6.q16-7 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagick++-6.q16hdri-7 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickcore-6.q16-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickcore-6.q16-3-extra –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickcore-6.q16hdri-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickcore-6.q16hdri-3-extra –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickwand-6.q16-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
libmagickwand-6.q16hdri-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm15  
16.04 LTS xenial imagemagick –  8:6.8.9.9-7ubuntu5.16+esm23  
imagemagick-6.q16 –  8:6.8.9.9-7ubuntu5.16+esm23  
libimage-magick-q16-perl –  8:6.8.9.9-7ubuntu5.16+esm23  
libmagick++-6.q16-5v5 –  8:6.8.9.9-7ubuntu5.16+esm23  
libmagickcore-6.q16-2 –  8:6.8.9.9-7ubuntu5.16+esm23  
libmagickcore-6.q16-2-extra –  8:6.8.9.9-7ubuntu5.16+esm23  
libmagickwand-6.q16-2 –  8:6.8.9.9-7ubuntu5.16+esm23  
14.04 LTS trusty imagemagick –  8:6.7.7.10-6ubuntu3.13+esm24  
libmagick++5 –  8:6.7.7.10-6ubuntu3.13+esm24  
libmagickcore5 –  8:6.7.7.10-6ubuntu3.13+esm24  
libmagickcore5-extra –  8:6.7.7.10-6ubuntu3.13+esm24  
libmagickwand5 –  8:6.7.7.10-6ubuntu3.13+esm24  
perlmagick –  8:6.7.7.10-6ubuntu3.13+esm24  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›