Amazon Linux 2 Security Advisory: ALAS2-2026-3278
Advisory Released Date: 2026-04-30
Advisory Updated Date: 2026-04-30
FAQs regarding Amazon Linux ALAS/CVE Severity
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue. (CVE-2026-33535)
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue. (CVE-2026-33536)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33899)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33905)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33908)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19. (CVE-2026-40169)
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-40310)
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-40311)
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19. (CVE-2026-40312)
Affected Packages:
ImageMagick
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update ImageMagick or yum update --advisory ALAS2-2026-3278 to update your system.
aarch64:
ImageMagick-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-devel-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-doc-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-perl-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-c++-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.aarch64
ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.aarch64
i686:
ImageMagick-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-devel-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-doc-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-perl-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-c++-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.i686
ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.i686
src:
ImageMagick-6.9.10.97-1.amzn2.0.26.src
x86_64:
ImageMagick-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-devel-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-doc-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-perl-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-c++-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.x86_64
ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.x86_64