Hi,
On 31/07/2026 21:33, Bastien Roucaries wrote:
imagemagick
--------------------
Release two DLA:
DLA 4680-1 fixing:
CVE-2026-53466 CVE-2026-53467 CVE-2026-55577 CVE-2026-55594
CVE-2026-55595 CVE-2026-55597 CVE-2026-55628 CVE-2026-56361
CVE-2026-56363 CVE-2026-56365 CVE-2026-56366 CVE-2026-56367
CVE-2026-56368 CVE-2026-56370 CVE-2026-56371 CVE-2026-56373
CVE-2026-56376 CVE-2026-56377 CVE-2026-56378
DLA 4696-1 fixing
CVE-2026-61464 CVE-2026-61465 CVE-2026-61857 CVE-2026-61858
CVE-2026-61859 CVE-2026-61860 CVE-2026-61862 CVE-2026-61863
CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61868
CVE-2026-61869 CVE-2026-61870 CVE-2026-61872
DSA 6383-1 fixing
CVE-2026-53466 CVE-2026-53467 CVE-2026-55577 CVE-2026-55594
CVE-2026-55597 CVE-2026-55628 CVE-2026-56361 CVE-2026-56363
CVE-2026-56364 CVE-2026-56365 CVE-2026-56367 CVE-2026-56368
CVE-2026-56370 CVE-2026-56371 CVE-2026-56376 CVE-2026-56377
CVE-2026-56378
Proposed a PU fixing remaining CVE #1142554 trixie-pu: package
imagemagick/8:7.1.1.43+dfsg1-1+deb13u12
For ELTS I released ELA-1766-1, ELA-1768-1 , ELA-1776-1, ELA-1778-1, ELA-1789-1
As usual with imagemagick progress was slow due to being ported between two
majors version.
It seems we're piling more and more CVE imagemagick fixes, with 150 to
250 patches per Debian dist, which I believe is hazardous in its own
right (and costly).
Do you think we should limit imagemagick fixes to moderate/high CVEs,
e.g. ignoring DoS/leaks?
Cheers!
Sylvain