vulnerability
Ubuntu: USN-8021-1 (CVE-2026-23876): ImageMagick vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:M/Au:N/C:C/I:C/A:C) | Jan 20, 2026 | Feb 11, 2026 | Mar 27, 2026 |
Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Jan 20, 2026
Added
Feb 11, 2026
Modified
Mar 27, 2026
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.
Solutions
ubuntu-pro-upgrade-imagemagickubuntu-pro-upgrade-imagemagick-6-q16ubuntu-pro-upgrade-imagemagick-6-q16hdriubuntu-pro-upgrade-imagemagick-commonubuntu-pro-upgrade-libimage-magick-q16-perlubuntu-pro-upgrade-libimage-magick-q16hdri-perlubuntu-pro-upgrade-libmagick-5ubuntu-pro-upgrade-libmagick-6-q16-5v5ubuntu-pro-upgrade-libmagick-6-q16-7ubuntu-pro-upgrade-libmagick-6-q16-8ubuntu-pro-upgrade-libmagick-6-q16-9t64ubuntu-pro-upgrade-libmagick-6-q16hdri-7ubuntu-pro-upgrade-libmagick-6-q16hdri-8ubuntu-pro-upgrade-libmagick-6-q16hdri-9t64ubuntu-pro-upgrade-libmagickcore-6-headersubuntu-pro-upgrade-libmagickcore-6-q16-2ubuntu-pro-upgrade-libmagickcore-6-q16-2-extraubuntu-pro-upgrade-libmagickcore-6-q16-3ubuntu-pro-upgrade-libmagickcore-6-q16-3-extraubuntu-pro-upgrade-libmagickcore-6-q16-6ubuntu-pro-upgrade-libmagickcore-6-q16-6-extraubuntu-pro-upgrade-libmagickcore-6-q16-7-extraubuntu-pro-upgrade-libmagickcore-6-q16-7t64ubuntu-pro-upgrade-libmagickcore-6-q16hdri-3ubuntu-pro-upgrade-libmagickcore-6-q16hdri-3-extraubuntu-pro-upgrade-libmagickcore-6-q16hdri-6ubuntu-pro-upgrade-libmagickcore-6-q16hdri-6-extraubuntu-pro-upgrade-libmagickcore-6-q16hdri-7-extraubuntu-pro-upgrade-libmagickcore-6-q16hdri-7t64ubuntu-pro-upgrade-libmagickcore5ubuntu-pro-upgrade-libmagickcore5-extraubuntu-pro-upgrade-libmagickwand-6-q16-2ubuntu-pro-upgrade-libmagickwand-6-q16-3ubuntu-pro-upgrade-libmagickwand-6-q16-6ubuntu-pro-upgrade-libmagickwand-6-q16-7t64ubuntu-pro-upgrade-libmagickwand-6-q16hdri-3ubuntu-pro-upgrade-libmagickwand-6-q16hdri-6ubuntu-pro-upgrade-libmagickwand-6-q16hdri-7t64ubuntu-pro-upgrade-libmagickwand5ubuntu-pro-upgrade-perlmagick
References
- CVE-2026-23876
- https://attackerkb.com/topics/CVE-2026-23876
- CWE-122
- CWE-190
- EUVD-EUVD-2026-3589
- UBUNTU-USN-8021-1
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3589
- https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8
- https://ubuntu.com/security/notices/USN-8021-1
- https://www.cve.org/CVERecord?id=CVE-2026-23876
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.