{"id":"USN-8558-1","summary":"imagemagick vulnerabilities","details":"It was discovered that ImageMagick did not limit mutual references between\nMVG files. An attacker could possibly use this issue to cause a stack\noverflow, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu\n22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-68950)\n\nIt was discovered that the ImageMagick MSL coder destroyed a cloned image\ntwice when an MSL script failed. An attacker could possibly use this issue\nto cause a use-after-free, resulting in a denial of service, or arbitrary\ncode execution. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04\nLTS. (CVE-2026-28688)\n\nIt was discovered that the ImageMagick VIFF image encoder did not properly\nvalidate the packet count, leading to an integer overflow on 32-bit\nsystems. An attacker could possibly use this issue to cause an out-of-\nbounds heap write, resulting in a denial of service. (CVE-2026-33900)\n\nIt was discovered that ImageMagick did not properly handle the column\noffset when sampling an image. An attacker could possibly use this issue to\ncause ImageMagick to read out of bounds, resulting in a denial of service.\nThis issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04\nLTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-33905)","modified":"2026-07-22T03:44:37.849919390Z","published":"2026-07-20T22:36:08Z","related":["UBUNTU-CVE-2025-68950","UBUNTU-CVE-2026-28688","UBUNTU-CVE-2026-33900","UBUNTU-CVE-2026-33905"],"upstream":["UBUNTU-CVE-2025-68950","UBUNTU-CVE-2026-28688","UBUNTU-CVE-2026-33900","UBUNTU-CVE-2026-33905"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8558-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-68950"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-28688"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-33900"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-33905"}],"affected":[{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.7.7.10-6ubuntu3.13+esm23"}]}],"versions":["8:6.7.7.10-5ubuntu3","8:6.7.7.10-5ubuntu4","8:6.7.7.10-6ubuntu1","8:6.7.7.10-6ubuntu2","8:6.7.7.10-6ubuntu3","8:6.7.7.10-6ubuntu3.1","8:6.7.7.10-6ubuntu3.2","8:6.7.7.10-6ubuntu3.3","8:6.7.7.10-6ubuntu3.4","8:6.7.7.10-6ubuntu3.5","8:6.7.7.10-6ubuntu3.6","8:6.7.7.10-6ubuntu3.7","8:6.7.7.10-6ubuntu3.8","8:6.7.7.10-6ubuntu3.9","8:6.7.7.10-6ubuntu3.11","8:6.7.7.10-6ubuntu3.12","8:6.7.7.10-6ubuntu3.13","8:6.7.7.10-6ubuntu3.13+esm1","8:6.7.7.10-6ubuntu3.13+esm2","8:6.7.7.10-6ubuntu3.13+esm3","8:6.7.7.10-6ubuntu3.13+esm4","8:6.7.7.10-6ubuntu3.13+esm5","8:6.7.7.10-6ubuntu3.13+esm6","8:6.7.7.10-6ubuntu3.13+esm7","8:6.7.7.10-6ubuntu3.13+esm8","8:6.7.7.10-6ubuntu3.13+esm9","8:6.7.7.10-6ubuntu3.13+esm10","8:6.7.7.10-6ubuntu3.13+esm11","8:6.7.7.10-6ubuntu3.13+esm12","8:6.7.7.10-6ubuntu3.13+esm13","8:6.7.7.10-6ubuntu3.13+esm14","8:6.7.7.10-6ubuntu3.13+esm15","8:6.7.7.10-6ubuntu3.13+esm16","8:6.7.7.10-6ubuntu3.13+esm17","8:6.7.7.10-6ubuntu3.13+esm18","8:6.7.7.10-6ubuntu3.13+esm19","8:6.7.7.10-6ubuntu3.13+esm20","8:6.7.7.10-6ubuntu3.13+esm21","8:6.7.7.10-6ubuntu3.13+esm22"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"imagemagick","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"},{"binary_name":"imagemagick-common","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"},{"binary_name":"libmagick++5","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"},{"binary_version":"8:6.7.7.10-6ubuntu3.13+esm23","binary_name":"libmagickcore5"},{"binary_name":"libmagickcore5-extra","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"},{"binary_name":"libmagickwand5","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"},{"binary_name":"perlmagick","binary_version":"8:6.7.7.10-6ubuntu3.13+esm23"}]},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-68950"},{"id":"CVE-2026-28688","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-33900"}],"ecosystem":"Ubuntu:Pro:14.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json"}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.8.9.9-7ubuntu5.16+esm22"}]}],"versions":["8:6.8.9.9-5ubuntu2","8:6.8.9.9-6","8:6.8.9.9-6build1","8:6.8.9.9-7","8:6.8.9.9-7ubuntu1","8:6.8.9.9-7ubuntu2","8:6.8.9.9-7ubuntu3","8:6.8.9.9-7ubuntu4","8:6.8.9.9-7ubuntu5","8:6.8.9.9-7ubuntu5.1","8:6.8.9.9-7ubuntu5.2","8:6.8.9.9-7ubuntu5.3","8:6.8.9.9-7ubuntu5.4","8:6.8.9.9-7ubuntu5.5","8:6.8.9.9-7ubuntu5.6","8:6.8.9.9-7ubuntu5.7","8:6.8.9.9-7ubuntu5.8","8:6.8.9.9-7ubuntu5.9","8:6.8.9.9-7ubuntu5.11","8:6.8.9.9-7ubuntu5.12","8:6.8.9.9-7ubuntu5.13","8:6.8.9.9-7ubuntu5.14","8:6.8.9.9-7ubuntu5.15","8:6.8.9.9-7ubuntu5.16","8:6.8.9.9-7ubuntu5.16+esm1","8:6.8.9.9-7ubuntu5.16+esm2","8:6.8.9.9-7ubuntu5.16+esm3","8:6.8.9.9-7ubuntu5.16+esm4","8:6.8.9.9-7ubuntu5.16+esm5","8:6.8.9.9-7ubuntu5.16+esm6","8:6.8.9.9-7ubuntu5.16+esm7","8:6.8.9.9-7ubuntu5.16+esm8","8:6.8.9.9-7ubuntu5.16+esm9","8:6.8.9.9-7ubuntu5.16+esm10","8:6.8.9.9-7ubuntu5.16+esm11","8:6.8.9.9-7ubuntu5.16+esm12","8:6.8.9.9-7ubuntu5.16+esm13","8:6.8.9.9-7ubuntu5.16+esm14","8:6.8.9.9-7ubuntu5.16+esm15","8:6.8.9.9-7ubuntu5.16+esm16","8:6.8.9.9-7ubuntu5.16+esm17","8:6.8.9.9-7ubuntu5.16+esm18","8:6.8.9.9-7ubuntu5.16+esm19","8:6.8.9.9-7ubuntu5.16+esm20","8:6.8.9.9-7ubuntu5.16+esm21"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"imagemagick","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_name":"imagemagick-common","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_name":"libimage-magick-perl","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_version":"8:6.8.9.9-7ubuntu5.16+esm22","binary_name":"libmagick++-6-headers"},{"binary_name":"libmagick++-6.q16-5v5","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_name":"libmagickcore-6-arch-config","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_version":"8:6.8.9.9-7ubuntu5.16+esm22","binary_name":"libmagickcore-6-headers"},{"binary_version":"8:6.8.9.9-7ubuntu5.16+esm22","binary_name":"libmagickcore-6.q16-2"},{"binary_name":"libmagickcore-6.q16-2-extra","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_version":"8:6.8.9.9-7ubuntu5.16+esm22","binary_name":"libmagickwand-6-headers"},{"binary_name":"libmagickwand-6.q16-2","binary_version":"8:6.8.9.9-7ubuntu5.16+esm22"},{"binary_version":"8:6.8.9.9-7ubuntu5.16+esm22","binary_name":"perlmagick"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json","cves_map":{"cves":[{"id":"CVE-2025-68950","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-28688","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33900","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33905","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:16.04:LTS"}}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"}]}],"versions":["8:6.9.7.4+dfsg-16ubuntu2","8:6.9.7.4+dfsg-16ubuntu3","8:6.9.7.4+dfsg-16ubuntu4","8:6.9.7.4+dfsg-16ubuntu5","8:6.9.7.4+dfsg-16ubuntu6","8:6.9.7.4+dfsg-16ubuntu6.2","8:6.9.7.4+dfsg-16ubuntu6.3","8:6.9.7.4+dfsg-16ubuntu6.4","8:6.9.7.4+dfsg-16ubuntu6.7","8:6.9.7.4+dfsg-16ubuntu6.8","8:6.9.7.4+dfsg-16ubuntu6.9","8:6.9.7.4+dfsg-16ubuntu6.11","8:6.9.7.4+dfsg-16ubuntu6.12","8:6.9.7.4+dfsg-16ubuntu6.13","8:6.9.7.4+dfsg-16ubuntu6.14","8:6.9.7.4+dfsg-16ubuntu6.15","8:6.9.7.4+dfsg-16ubuntu6.15+esm1","8:6.9.7.4+dfsg-16ubuntu6.15+esm2","8:6.9.7.4+dfsg-16ubuntu6.15+esm3","8:6.9.7.4+dfsg-16ubuntu6.15+esm4","8:6.9.7.4+dfsg-16ubuntu6.15+esm5","8:6.9.7.4+dfsg-16ubuntu6.15+esm6","8:6.9.7.4+dfsg-16ubuntu6.15+esm7","8:6.9.7.4+dfsg-16ubuntu6.15+esm8","8:6.9.7.4+dfsg-16ubuntu6.15+esm9","8:6.9.7.4+dfsg-16ubuntu6.15+esm10","8:6.9.7.4+dfsg-16ubuntu6.15+esm11","8:6.9.7.4+dfsg-16ubuntu6.15+esm12","8:6.9.7.4+dfsg-16ubuntu6.15+esm13"],"ecosystem_specific":{"binaries":[{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"imagemagick"},{"binary_name":"imagemagick-6-common","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"imagemagick-6.q16hdri","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"imagemagick-common"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libimage-magick-perl"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libimage-magick-q16hdri-perl"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libmagick++-6-headers"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libmagick++-6.q16-7"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libmagick++-6.q16hdri-7"},{"binary_name":"libmagickcore-6-arch-config","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickcore-6-headers","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickcore-6.q16-3","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickcore-6.q16-3-extra","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickcore-6.q16hdri-3","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickcore-6.q16hdri-3-extra","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickwand-6-headers","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_name":"libmagickwand-6.q16-3","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"},{"binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14","binary_name":"libmagickwand-6.q16hdri-3"},{"binary_name":"perlmagick","binary_version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm14"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"id":"CVE-2025-68950","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-28688","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33900","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-33905"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json"}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"}]}],"versions":["8:6.9.10.23+dfsg-2.1ubuntu3","8:6.9.10.23+dfsg-2.1ubuntu8","8:6.9.10.23+dfsg-2.1ubuntu9","8:6.9.10.23+dfsg-2.1ubuntu10","8:6.9.10.23+dfsg-2.1ubuntu11","8:6.9.10.23+dfsg-2.1ubuntu11.1","8:6.9.10.23+dfsg-2.1ubuntu11.2","8:6.9.10.23+dfsg-2.1ubuntu11.4","8:6.9.10.23+dfsg-2.1ubuntu11.4+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.5","8:6.9.10.23+dfsg-2.1ubuntu11.6","8:6.9.10.23+dfsg-2.1ubuntu11.6+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.7","8:6.9.10.23+dfsg-2.1ubuntu11.7+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.9","8:6.9.10.23+dfsg-2.1ubuntu11.9+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.9+esm2","8:6.9.10.23+dfsg-2.1ubuntu11.10","8:6.9.10.23+dfsg-2.1ubuntu11.10+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.11","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm1","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm2","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm3","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm4","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm5","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm6","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm7","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm8","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm9","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm10","8:6.9.10.23+dfsg-2.1ubuntu11.11+esm11"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"imagemagick","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"imagemagick-6-common","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"imagemagick-6.q16hdri","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"imagemagick-common","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libimage-magick-perl"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libimage-magick-q16hdri-perl"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libmagick++-6-headers"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libmagick++-6.q16-8"},{"binary_name":"libmagick++-6.q16hdri-8","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libmagickcore-6-arch-config"},{"binary_name":"libmagickcore-6-headers","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"libmagickcore-6.q16-6","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"libmagickcore-6.q16-6-extra","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"libmagickcore-6.q16hdri-6","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libmagickcore-6.q16hdri-6-extra"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"libmagickwand-6-headers"},{"binary_name":"libmagickwand-6.q16-6","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_name":"libmagickwand-6.q16hdri-6","binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12"},{"binary_version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm12","binary_name":"perlmagick"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-68950"},{"id":"CVE-2026-28688","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33900","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33905","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json"}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"}]}],"versions":["8:6.9.11.60+dfsg-1ubuntu1","8:6.9.11.60+dfsg-1.3","8:6.9.11.60+dfsg-1.3build1","8:6.9.11.60+dfsg-1.3build2","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.1+esm1","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.2","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.2+esm1","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm1","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm2","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+esm3","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm1","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm2","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm3","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm4","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm5","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm6","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm7","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm8","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm9","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10","8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm11"],"ecosystem_specific":{"binaries":[{"binary_name":"imagemagick","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"imagemagick-6-common","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"imagemagick-6.q16hdri","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"imagemagick-common","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libimage-magick-perl","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libimage-magick-q16hdri-perl","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagick++-6-headers","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagick++-6.q16-8","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagick++-6.q16hdri-8","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagickcore-6-arch-config","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12","binary_name":"libmagickcore-6-headers"},{"binary_name":"libmagickcore-6.q16-6","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12","binary_name":"libmagickcore-6.q16-6-extra"},{"binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12","binary_name":"libmagickcore-6.q16hdri-6"},{"binary_name":"libmagickcore-6.q16hdri-6-extra","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagickwand-6-headers","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_name":"libmagickwand-6.q16-6","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"},{"binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12","binary_name":"libmagickwand-6.q16hdri-6"},{"binary_name":"perlmagick","binary_version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm12"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-68950","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-28688"},{"id":"CVE-2026-33900","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-33905","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json"}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"}]}],"versions":["8:6.9.11.60+dfsg-1.6ubuntu1","8:6.9.12.98+dfsg1-5","8:6.9.12.98+dfsg1-5.2build1","8:6.9.12.98+dfsg1-5.2build2","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm1","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm3","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm4","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm5","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm6","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm7","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm8","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm9","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm10"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"imagemagick","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"imagemagick-6-common","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"imagemagick-6.q16hdri"},{"binary_name":"libimage-magick-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libimage-magick-q16hdri-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libmagick++-6-headers","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libmagick++-6.q16-9t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"libmagick++-6.q16hdri-9t64"},{"binary_name":"libmagickcore-6-arch-config","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"libmagickcore-6-headers"},{"binary_name":"libmagickcore-6.q16-7-extra","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libmagickcore-6.q16-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"libmagickcore-6.q16hdri-7-extra"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"libmagickcore-6.q16hdri-7t64"},{"binary_name":"libmagickwand-6-headers","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_name":"libmagickwand-6.q16-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11","binary_name":"libmagickwand-6.q16hdri-7t64"},{"binary_name":"perlmagick","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json","cves_map":{"cves":[{"id":"CVE-2025-68950","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-28688","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-33900","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-33905","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:24.04:LTS"}}},{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/imagemagick?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"}]}],"versions":["8:7.1.2.3+dfsg1-1","8:7.1.2.8+dfsg1-1","8:7.1.2.12+dfsg1-1","8:7.1.2.13+dfsg1-1","8:7.1.2.15+dfsg1-1","8:7.1.2.16+dfsg1-1","8:7.1.2.18+dfsg1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"imagemagick","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"imagemagick-7-common"},{"binary_name":"imagemagick-7.q16","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"imagemagick-7.q16hdri"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"libimage-magick-perl"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libimage-magick-q16hdri-perl","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"libmagick++-7-headers"},{"binary_name":"libmagick++-7.q16-5","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagick++-7.q16hdri-5","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"libmagickcore-7-arch-config"},{"binary_name":"libmagickcore-7-headers","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickcore-7.q16-10","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickcore-7.q16-10-extra","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickcore-7.q16hdri-10","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickcore-7.q16hdri-10-extra","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickwand-7-headers","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickwand-7.q16-10","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_name":"libmagickwand-7.q16hdri-10","binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1"},{"binary_version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm1","binary_name":"perlmagick"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8558-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:26.04:LTS","cves":[{"id":"CVE-2026-33900","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-33905"}]}}}],"schema_version":"1.7.5"}