Ubuntu 7179 Published by

Ubuntu released security notices USN-8626-1 and USN-8592-1 to address critical flaws in systemd and ImageMagick. The systemd patches resolve three vulnerabilities that could allow local attackers to escalate privileges, terminate privileged processes, or crash system services through improperly validated requests. The ImageMagick updates fix four separate issues involving malformed image handling, out-of-bounds heap writes, and integer overflows that could lead to arbitrary code execution or denial of service.

[USN-8626-1] systemd vulnerabilities
[USN-8592-1] ImageMagick vulnerabilities




[USN-8626-1] systemd vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8626-1
August 10, 2026

systemd vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in systemd.

Software Description:
- systemd: system and service manager

Details:

It was discovered that systemd-homed did not properly verify the signature
of home records. A local attacker could possibly use this issue to add
arbitrary system groups to a logged-in user and gain elevated privileges.
(CVE-2026-16742)

It was discovered that systemd-machined incorrectly handled certain polkit
authorization checks. A local attacker could possibly use this issue to
terminate arbitrary processes, including privileged ones. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-15060)

It was discovered that systemd-oomd did not properly validate certain IPC
requests. A local attacker could possibly use this issue to terminate
arbitrary processes. (CVE-2026-15059)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
systemd 259.5-0ubuntu3.4
systemd-homed 259.5-0ubuntu3.4
systemd-oomd 259.5-0ubuntu3.4

Ubuntu 24.04 LTS
systemd 255.4-1ubuntu8.17
systemd-homed 255.4-1ubuntu8.17
systemd-oomd 255.4-1ubuntu8.17

Ubuntu 22.04 LTS
systemd 249.11-0ubuntu3.22
systemd-oomd 249.11-0ubuntu3.22

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8626-1
CVE-2026-15059, CVE-2026-15060, CVE-2026-16742

Package Information:
https://launchpad.net/ubuntu/+source/systemd/259.5-0ubuntu3.4
https://launchpad.net/ubuntu/+source/systemd/255.4-1ubuntu8.17
https://launchpad.net/ubuntu/+source/systemd/249.11-0ubuntu3.22



[USN-8592-1] ImageMagick vulnerabilities


==========================================================================
Ubuntu Security Notice USN-8592-1
August 10, 2026

imagemagick vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in ImageMagick.

Software Description:
- imagemagick: Image manipulation programs and library

Details:

Hao Ren discovered that ImageMagick incorrectly handled certain images
when using the wavelet-denoise operation. An attacker could possibly use
this issue to trigger an out-of-bounds heap write, resulting in
arbitrary code execution. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-30936)

It was discovered that ImageMagick incorrectly handled extremely large
XWD images. An attacker could possibly use this issue to trigger an
out-of-bounds heap write, resulting in arbitrary code execution.
(CVE-2026-30937)

It was discovered that ImageMagick incorrectly handled extremely large
SFW images on 32-bit systems. An attacker could possibly use this issue
to trigger an integer overflow, resulting in a denial of service.
(CVE-2026-31853)

It was discovered that ImageMagick incorrectly handled memory allocation
failures in the sixel encoder. An attacker could possibly use this issue
to trigger a stack buffer overflow, resulting in arbitrary code
execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-32259)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
imagemagick 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
imagemagick-6.q16 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
imagemagick-6.q16hdri 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libimage-magick-q16-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libimage-magick-q16hdri-perl 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagick++-6.q16-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagick++-6.q16hdri-9t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickcore-6.q16-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickcore-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickcore-6.q16hdri-7-extra 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickcore-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickwand-6.q16-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro
libmagickwand-6.q16hdri-7t64 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm12
Available with Ubuntu Pro

Ubuntu 22.04 LTS
imagemagick 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
imagemagick-6.q16 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
imagemagick-6.q16hdri 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libimage-magick-q16-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libimage-magick-q16hdri-perl 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagick++-6.q16-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagick++-6.q16hdri-8 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickcore-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickcore-6.q16-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickcore-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickcore-6.q16hdri-6-extra 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickwand-6.q16-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro
libmagickwand-6.q16hdri-6 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm13
Available with Ubuntu Pro

Ubuntu 20.04 LTS
imagemagick 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libimage-magick-q16-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libimage-magick-q16hdri-perl 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libmagickcore-6.q16-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libmagickcore-6.q16hdri-6-extra 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libmagickwand-6.q16-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro
libmagickwand-6.q16hdri-6 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm13
Available with Ubuntu Pro

Ubuntu 18.04 LTS
imagemagick-6.q16 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
imagemagick-6.q16hdri 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libimage-magick-q16-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libimage-magick-q16hdri-perl 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagick++-6.q16-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagick++-6.q16hdri-7 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickcore-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickcore-6.q16-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickcore-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickcore-6.q16hdri-3-extra 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickwand-6.q16-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro
libmagickwand-6.q16hdri-3 8:6.9.7.4+dfsg-16ubuntu6.15+esm15
Available with Ubuntu Pro

Ubuntu 16.04 LTS
imagemagick 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
libimage-magick-q16-perl 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro
libmagickwand-6.q16-2 8:6.8.9.9-7ubuntu5.16+esm23
Available with Ubuntu Pro

Ubuntu 14.04 LTS
imagemagick 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro
libmagick++5 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro
libmagickcore5 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro
libmagickcore5-extra 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro
libmagickwand5 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro
perlmagick 8:6.7.7.10-6ubuntu3.13+esm24
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8592-1
CVE-2026-30936, CVE-2026-30937, CVE-2026-31853, CVE-2026-32259