<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T06:35:33.462612+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00323</id>
    <title>bdu:2026-00323</title>
    <updated>2026-10-07T06:35:33.476488+00:00</updated>
    <content>bdu:2026-00323</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329319</id>
    <title>EUVD-2026-329319</title>
    <updated>2026-10-07T06:35:33.476531+00:00</updated>
    <content>EUVD-2026-329319</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65955</id>
    <title>fkie_cve-2025-65955</title>
    <updated>2026-10-07T06:35:33.476546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&gt;font, freeing the font string but leaving _drawInfo-&gt;font pointing to freed memory while _drawInfo-&gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-65955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q3hc-j9x5-mp9m</id>
    <title>Withdrawn: GHSA-q3hc-j9x5-mp9m — Withdrawn Advisory: ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family</title>
    <updated>2026-10-07T06:35:33.476585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-arm64 and 8 more</p>
<p>## Withdrawn Advisory
This advisory has been withdrawn because it does not affect the ImageMagick project's NuGet packages.</p>
<p>### Original Description
We believe that we have discovered a potential security vulnerability in ImageMagick’s Magick++ layer that manifests when `Options::fontFamily` is invoked with an empty string.</p>
<p>**Vulnerability Details**
- Clearing a font family calls `RelinquishMagickMemory` on `_drawInfo-&gt;font`, freeing the font string but leaving `_drawInfo-&gt;font` pointing to freed memory while `_drawInfo-&gt;family` is set to that (now-invalid) pointer. Any later cleanup or reuse of `_drawInfo-&gt;font` re-frees or dereferences dangling memory.
- `DestroyDrawInfo` and other setters (`Options::font`, `Image::font`) assume `_drawInfo-&gt;font` remains valid, so destruction or subsequent updates trigger crashes or heap corruption.</p>
<p>```cpp
if (family_.length() == 0)
  {
    _drawInfo-&gt;family=(char *) RelinquishMagickMemory(_drawInfo-&gt;font);
    DestroyString(RemoveImageOption(imageInfo(),"family"));
  }
```</p>
<p>- **CWE-416 (Use After Free):** `_drawInfo-&gt;font` is left dangling yet still reachable through the Options object.
- **CWE-415 (Double Free):** DrawInfo teardown frees `_drawInfo-&gt;font` again, provoking allocator aborts.</p>
<p>**Affected Versions**
- Introduced by commit `6409f34d637a34a1c643632aa849371ec8b3b5a8` (“Added fontFamily to the Image class of Magick++”, 2015-08-01, blame line 313).
- Present in all releases that include that commit, at least ImageMagick 7.0.1-…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q3hc-j9x5-mp9m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2791</id>
    <title>OESA-2025-2791 — ImageMagick security update</title>
    <updated>2026-10-07T06:35:33.476662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: ImageMagick</p>
<p>Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.

Security Fix(es):</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;gt;font, freeing the font string but leaving _drawInfo-&amp;gt;font pointing to freed memory while _drawInfo-&amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.(CVE-2025-65955)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2791"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15816-1</id>
    <title>openSUSE-SU-2025:15816-1 — ImageMagick-7.1.2.10-1.1 on GA media</title>
    <updated>2026-10-07T06:35:33.476697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick-7.1.2.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15816-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:4428-1</id>
    <title>SUSE-SU-2025:4428-1 — Security update for ImageMagick</title>
    <updated>2026-10-07T06:35:33.476716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ImageMagick</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:4428-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65955</id>
    <title>Withdrawn: UBUNTU-CVE-2025-65955</title>
    <updated>2026-10-07T06:35:33.476733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick, Ubuntu:25.04: imagemagick</p>
<p>ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&gt;font, freeing the font string but leaving _drawInfo-&gt;font pointing to freed memory while _drawInfo-&gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65955"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2722</id>
    <title>WID-SEC-W-2025-2722 — ImageMagick: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-07T06:35:33.476769+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2722"/>
  </entry>
</feed>
