<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:03:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00323</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00323</link>
      <description>bdu:2026-00323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00323</guid>
    </item>
    <item>
      <title>EUVD-2026-329319</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329319</link>
      <description>EUVD-2026-329319</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329319</guid>
    </item>
    <item>
      <title>fkie_cve-2025-65955</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-65955</link>
      <description>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;gt;font, freeing the font string but leaving _drawInfo-&amp;gt;font pointing to freed memory while _drawInfo-&amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;gt;font, freeing the font string but leaving _drawInfo-&amp;gt;font pointing to freed memory while _drawInfo-&amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-65955</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-q3hc-j9x5-mp9m — Withdrawn Advisory: ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q3hc-j9x5-mp9m</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-arm64 and 8 more&lt;/p&gt;
&lt;p&gt;## Withdrawn Advisory
This advisory has been withdrawn because it does not affect the ImageMagick project&amp;#39;s NuGet packages.&lt;/p&gt;
&lt;p&gt;### Original Description
We believe that we have discovered a potential security vulnerability in ImageMagick’s Magick++ layer that manifests when `Options::fontFamily` is invoked with an empty string.&lt;/p&gt;
&lt;p&gt;**Vulnerability Details**
- Clearing a font family calls `RelinquishMagickMemory` on `_drawInfo-&amp;gt;font`, freeing the font string but leaving `_drawInfo-&amp;gt;font` pointing to freed memory while `_drawInfo-&amp;gt;family` is set to that (now-invalid) pointer. Any later cleanup or reuse of `_drawInfo-&amp;gt;font` re-frees or dereferences dangling memory.
- `DestroyDrawInfo` and other setters (`Options::font`, `Image::font`) assume `_drawInfo-&amp;gt;font` remains valid, so destruction or subsequent updates trigger crashes or heap corruption.&lt;/p&gt;
&lt;p&gt;```cpp
if (family_.length() == 0)
  {
    _drawInfo-&amp;gt;family=(char *) RelinquishMagickMemory(_drawInfo-&amp;gt;font);
    DestroyString(RemoveImageOption(imageInfo(),&amp;#34;family&amp;#34;));
  }
```&lt;/p&gt;
&lt;p&gt;- **CWE-416 (Use After Free):** `_drawInfo-&amp;gt;font` is left dangling yet still reachable through the Options object.
- **CWE-415 (Double Free):** DrawInfo teardown frees `_drawInfo-&amp;gt;font` again, provoking allocator aborts.&lt;/p&gt;
&lt;p&gt;**Affected Versions**
- Introduced by commit `6409f34d637a34a1c643632aa849371ec8b3b5a8` (“Added fontFamily to the Image class of Magick++”, 2015-08-01, blame line 313).
- Present in all releases that include that commit, at least ImageMagick 7.0.1-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-OpenMP-arm64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-arm64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q16-arm64 and 8 more&lt;/p&gt;
&lt;p&gt;## Withdrawn Advisory
This advisory has been withdrawn because it does not affect the ImageMagick project&amp;#39;s NuGet packages.&lt;/p&gt;
&lt;p&gt;### Original Description
We believe that we have discovered a potential security vulnerability in ImageMagick’s Magick++ layer that manifests when `Options::fontFamily` is invoked with an empty string.&lt;/p&gt;
&lt;p&gt;**Vulnerability Details**
- Clearing a font family calls `RelinquishMagickMemory` on `_drawInfo-&amp;gt;font`, freeing the font string but leaving `_drawInfo-&amp;gt;font` pointing to freed memory while `_drawInfo-&amp;gt;family` is set to that (now-invalid) pointer. Any later cleanup or reuse of `_drawInfo-&amp;gt;font` re-frees or dereferences dangling memory.
- `DestroyDrawInfo` and other setters (`Options::font`, `Image::font`) assume `_drawInfo-&amp;gt;font` remains valid, so destruction or subsequent updates trigger crashes or heap corruption.&lt;/p&gt;
&lt;p&gt;```cpp
if (family_.length() == 0)
  {
    _drawInfo-&amp;gt;family=(char *) RelinquishMagickMemory(_drawInfo-&amp;gt;font);
    DestroyString(RemoveImageOption(imageInfo(),&amp;#34;family&amp;#34;));
  }
```&lt;/p&gt;
&lt;p&gt;- **CWE-416 (Use After Free):** `_drawInfo-&amp;gt;font` is left dangling yet still reachable through the Options object.
- **CWE-415 (Double Free):** DrawInfo teardown frees `_drawInfo-&amp;gt;font` again, provoking allocator aborts.&lt;/p&gt;
&lt;p&gt;**Affected Versions**
- Introduced by commit `6409f34d637a34a1c643632aa849371ec8b3b5a8` (“Added fontFamily to the Image class of Magick++”, 2015-08-01, blame line 313).
- Present in all releases that include that commit, at least ImageMagick 7.0.1-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q3hc-j9x5-mp9m</guid>
    </item>
    <item>
      <title>OESA-2025-2791 — ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2791</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;amp;gt;font, freeing the font string but leaving _drawInfo-&amp;amp;gt;font pointing to freed memory while _drawInfo-&amp;amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.(CVE-2025-65955)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;amp;gt;font, freeing the font string but leaving _drawInfo-&amp;amp;gt;font pointing to freed memory while _drawInfo-&amp;amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.(CVE-2025-65955)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2791</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15816-1 — ImageMagick-7.1.2.10-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15816-1</link>
      <description>&lt;p&gt;ImageMagick-7.1.2.10-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick-7.1.2.10-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15816-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:4428-1 — Security update for ImageMagick</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:4428-1</link>
      <description>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:4428-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-65955</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65955</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick, Ubuntu:25.04: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;gt;font, freeing the font string but leaving _drawInfo-&amp;gt;font pointing to freed memory while _drawInfo-&amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick, Ubuntu:25.10: imagemagick, Ubuntu:25.04: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo-&amp;gt;font, freeing the font string but leaving _drawInfo-&amp;gt;font pointing to freed memory while _drawInfo-&amp;gt;family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo-&amp;gt;font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo-&amp;gt;font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-65955</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2722 — ImageMagick: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2722</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2722</guid>
    </item>
  </channel>
</rss>
