USN-8127-1: ImageMagick vulnerabilities

Publication date

30 March 2026

Overview

Several security issues were fixed in ImageMagick.


Packages

  • imagemagick - Image manipulation programs and library

Details

It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)

It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)

It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)

It was discovered that ImageMagick incorrectly handled certain specially
crafted image files. An attacker could possibly use this issue to...

It was discovered that ImageMagick did not properly process certain tags
prior to an image being loaded. An attacker could possibly use this issue
to cause ImageMagick to crash, resulting in a denial of service.
(CVE-2026-23952)

It was discovered that ImageMagick did not properly handle temporary file
creation failures. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25795)

It was discovered that ImageMagick did not properly manage memory under
certain conditions. An attacker could possibly use this issue to cause
ImageMagick to consume resources, resulting in a denial of service.
(CVE-2026-25796)

It was discovered that ImageMagick incorrectly handled certain specially
crafted image files. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25798)

It was discovered that ImageMagick did not properly validate certain YUV
sampling factors. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. (CVE-2026-25799)

It was discovered that ImageMagick incorrectly handled certain specially
crafted image files. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-25970)

It was discovered that ImageMagick incorrectly managed memory when handling
certain specially crafted image files. An attacker could possibly use this
issue to cause ImageMagick to consume resources, resulting in a denial of
service. (CVE-2026-25988)

It was discovered that ImageMagick incorrectly handled certain crafted image
profiles. An attacker could possibly use this issue to cause ImageMagick
to consume available resources, resulting in a denial of service.
(CVE-2026-26066)

It was discovered that ImageMagick incorrectly handled large image profiles
when encoding PNG images. An attacker could use this issue to cause
ImageMagick to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-30883)

Kamil Frankowicz discovered that ImageMagick incorrectly handled certain XML
data. An attacker could possibly use this issue to cause ImageMagick to crash,
resulting in a denial of service. (CVE-2026-32636)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble imagemagick-6.q16 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
imagemagick-6.q16hdri –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libimage-magick-q16-perl –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libimage-magick-q16hdri-perl –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagick++-6.q16-9t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagick++-6.q16hdri-9t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickcore-6-headers –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickcore-6.q16-7-extra –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickcore-6.q16-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickcore-6.q16hdri-7-extra –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickcore-6.q16hdri-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickwand-6.q16-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
libmagickwand-6.q16hdri-7t64 –  8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8  
22.04 LTS jammy imagemagick-6.q16 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
imagemagick-6.q16hdri –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libimage-magick-q16-perl –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libimage-magick-q16hdri-perl –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagick++-6.q16-8 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagick++-6.q16hdri-8 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickcore-6.q16-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickcore-6.q16-6-extra –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickcore-6.q16hdri-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickcore-6.q16hdri-6-extra –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickwand-6.q16-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
libmagickwand-6.q16hdri-6 –  8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9  
20.04 LTS focal libimage-magick-q16-perl –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
libimage-magick-q16hdri-perl –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
libmagickcore-6.q16-6 –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
libmagickcore-6.q16-6-extra –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
libmagickcore-6.q16hdri-6 –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
libmagickcore-6.q16hdri-6-extra –  8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9  
18.04 LTS bionic imagemagick-6.q16 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
imagemagick-6.q16hdri –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libimage-magick-q16-perl –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libimage-magick-q16hdri-perl –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagick++-6.q16-7 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagick++-6.q16hdri-7 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickcore-6.q16-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickcore-6.q16-3-extra –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickcore-6.q16hdri-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickcore-6.q16hdri-3-extra –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickwand-6.q16-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
libmagickwand-6.q16hdri-3 –  8:6.9.7.4+dfsg-16ubuntu6.15+esm11  
16.04 LTS xenial imagemagick-6.q16 –  8:6.8.9.9-7ubuntu5.16+esm19  
libimage-magick-q16-perl –  8:6.8.9.9-7ubuntu5.16+esm19  
libmagick++-6.q16-5v5 –  8:6.8.9.9-7ubuntu5.16+esm19  
libmagickcore-6.q16-2 –  8:6.8.9.9-7ubuntu5.16+esm19  
libmagickcore-6.q16-2-extra –  8:6.8.9.9-7ubuntu5.16+esm19  
libmagickwand-6-headers –  8:6.8.9.9-7ubuntu5.16+esm19  
libmagickwand-6.q16-2 –  8:6.8.9.9-7ubuntu5.16+esm19  
14.04 LTS trusty imagemagick –  8:6.7.7.10-6ubuntu3.13+esm20  
imagemagick-common –  8:6.7.7.10-6ubuntu3.13+esm20  
libmagick++5 –  8:6.7.7.10-6ubuntu3.13+esm20  
libmagickcore5 –  8:6.7.7.10-6ubuntu3.13+esm20  
libmagickcore5-extra –  8:6.7.7.10-6ubuntu3.13+esm20  
libmagickwand5 –  8:6.7.7.10-6ubuntu3.13+esm20  
perlmagick –  8:6.7.7.10-6ubuntu3.13+esm20  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›