CVE-2026-28687 Unknown

CVE-2026-28687

SUSE Released: April 16, 2026 Updated: April 21, 2026 Restart Required

Description

CVE-2026-28687 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41. The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).

Fixed Vulnerabilities 1

CVE-2026-28687 N/A 0.0 ⚠️ KEV fixed
Mar 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's…

Quick Info

Patch ID: CVE-2026-28687
Vendor: SUSE
Severity: Unknown
CVEs Fixed: 1
Restart: Required

Vendor

SUSE

Additional Info

advisory id: CVE-2026-28687
advisory type: Security Update
cvrf filename: cvrf-CVE-2026-28687.xml

Share