ALAS2-2026-3278


Amazon Linux 2 Security Advisory: ALAS2-2026-3278
Advisory Released Date: 2026-04-30
Advisory Updated Date: 2026-04-30
Severity: Important

Issue Overview:

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, an out-of-bounds write of a zero byte exists in the X11 `display` interaction path that could lead to a crash. Versions 7.1.2-18 and 6.9.13-43 patch the issue. (CVE-2026-33535)

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9.13-43, due to an incorrect return value on certain platforms a pointer is incremented past the end of a buffer that is on the stack and that could result in an out of bounds write. Versions 7.1.2-18 and 6.9.13-43 patch the issue. (CVE-2026-33536)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33899)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33905)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-33908)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19. (CVE-2026-40169)

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-40310)

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19. (CVE-2026-40311)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19. (CVE-2026-40312)


Affected Packages:

ImageMagick


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update ImageMagick or yum update --advisory ALAS2-2026-3278 to update your system.

New Packages:
aarch64:
    ImageMagick-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-devel-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-doc-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-perl-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-c++-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.aarch64
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.aarch64

i686:
    ImageMagick-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-devel-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-doc-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-perl-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-c++-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.i686
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.i686

src:
    ImageMagick-6.9.10.97-1.amzn2.0.26.src

x86_64:
    ImageMagick-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-devel-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-doc-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-perl-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-c++-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-c++-devel-6.9.10.97-1.amzn2.0.26.x86_64
    ImageMagick-debuginfo-6.9.10.97-1.amzn2.0.26.x86_64