[CLSA-2026:1786092614] Fix CVE(s): CVE-2025-66628, CVE-2026-24485, CVE-2026-25989
Type:
security
Severity:
Important
Release date:
2026-08-07 08:50:25 UTC
Description:
* SECURITY UPDATE: integer overflow in the TIM reader - debian/patches/CVE-2025-66628.patch: guard the image_size computation in ReadTIMImage with HeapOverflowSanityCheckGetSize (coders/tim.c). Upstream's companion "image_size > GetBlobSize(image)" early reject is deliberately not carried: GetBlobSize is only authoritative for regular files and in-memory blobs, so it would reject valid TIM images read from a FIFO, from stdin or a pipe, or from a gzip/bzip2 stream - CVE-2025-66628 * SECURITY UPDATE: infinite loop in the PCD reader on a missing Sync marker - debian/patches/CVE-2026-24485.patch: track the ReadBlob return in the PCDGetBits macro and bail out on a short read, and carry the upstream prerequisite that makes the Sync search and the decode loop terminate on EOF -- without it the macro's bare "break" only leaves the innermost recovery loop and DecodeImage still spins (coders/pcd.c) - CVE-2026-24485 * SECURITY UPDATE: off-by-one out-of-range cast in the CastDouble* helpers - debian/patches/CVE-2026-25989.patch: reject a value equal to the type maximum in CastDoubleToLong and CastDoubleToQuantumAny (magick/image-private.h) - CVE-2026-25989
Updated packages:
  • imagemagick_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:4c12d54de1ac018151a109d041f57121c327be67
  • imagemagick-6.q16_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:4dc2cdfb1ee1456dff5aab086374e8dba3e56b08
  • imagemagick-common_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:d6d39c87835bc1fd92180c50cad71948c5c9c67a
  • imagemagick-doc_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:bb11e8a969d0bf18d406b48fa94d8ac71024330b
  • libimage-magick-perl_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:79a3efedb7acfa5f1cde77c1871d30e38e4667f2
  • libimage-magick-q16-perl_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:c3b73b4b312a313f0c728674b56b6775e21d6a3f
  • libmagick++-6-headers_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:7ddcd41e18f67d9390fafe8631fb3f4c35d9173a
  • libmagick++-6.q16-5v5_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:cb806cc721f12df723939f3114196fdac4a6da28
  • libmagick++-6.q16-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:b23ca103764a001b10bfc9a330942f43807f4aab
  • libmagick++-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:099366fb1c1a4e4ad07103d244d10e48d71b993b
  • libmagickcore-6-arch-config_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:7806103973d6518019649e8503013b46afe5f3aa
  • libmagickcore-6-headers_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:1f7e9a65855e13d6f5b1daad3ac465a51355a6b6
  • libmagickcore-6.q16-2_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:a5894a3c52abdea20399800a0396d6268513e1cc
  • libmagickcore-6.q16-2-extra_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:ad0d56b7aa3edf878d64898db1ad473fc11721b7
  • libmagickcore-6.q16-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:29297d1b0abcf8e9c3be27f77377e79d7c01f992
  • libmagickcore-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:855ed0799213c93adf6a5b5fae777de22a8536ac
  • libmagickwand-6-headers_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:278874005e70c667c62826c8e0b4a427dbd1b3b5
  • libmagickwand-6.q16-2_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:0126767fe5e0faad8e679379dc1f213731e84709
  • libmagickwand-6.q16-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_amd64.deb
    sha:b1f1538b931cb12df9d6b404531f70cf82cbe554
  • libmagickwand-dev_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:9abac93fadb970b38a0cc840f77811a24e533341
  • perlmagick_6.8.9.9-7ubuntu5.17+tuxcare.els58_all.deb
    sha:0935452e9266cb5b57f23c9c1a5022f71074096e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.