Bug 34163 - graphicsmagick new security issues CVE-2025-2779[56]
Summary: graphicsmagick new security issues CVE-2025-2779[56]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-03 16:28 CEST by Nicolas Salguero
Modified: 2025-04-12 06:24 CEST (History)
3 users (show)

See Also:
Source RPM: graphicsmagick-1.3.40-1.mga9.src.rpm, graphicsmagick-1.3.40-1.mga9.tainted.src.rpm
CVE: CVE-2025-27795
Status comment:


Attachments

Description Nicolas Salguero 2025-04-03 16:28:41 CEST
SUSE has issued an advisory on April 3:
https://lwn.net/Articles/1016352/
Comment 1 Nicolas Salguero 2025-04-03 16:29:59 CEST
Fix: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/9bbae7314e3c3b19b830591010ed90bb136b9c42

Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-27795
Source RPM: (none) => graphicsmagick

Nicolas Salguero 2025-04-03 16:30:12 CEST

Status comment: (none) => Patch available from upstream

Comment 2 Nicolas Salguero 2025-04-04 09:24:02 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits. (CVE-2025-27795)

References:
https://lwn.net/Articles/1016352/
========================

Updated packages in core/updates_testing:
========================
graphicsmagick-1.3.40-1.1.mga9
graphicsmagick-doc-1.3.40-1.1.mga9
lib(64)graphicsmagick++12-1.3.40-1.1.mga9
lib(64)graphicsmagick3-1.3.40-1.1.mga9
lib(64)graphicsmagick-devel-1.3.40-1.1.mga9
lib(64)graphicsmagickwand2-1.3.40-1.1.mga9
perl-Graphics-Magick-1.3.40-1.1.mga9

from SRPM:
graphicsmagick-1.3.40-1.1.mga9.src.rpm

Updated packages in tainted/updates_testing:
========================
graphicsmagick-1.3.40-1.1.mga9.tainted
graphicsmagick-doc-1.3.40-1.1.mga9.tainted
lib(64)graphicsmagick++12-1.3.40-1.1.mga9.tainted
lib(64)graphicsmagick3-1.3.40-1.1.mga9.tainted
lib(64)graphicsmagick-devel-1.3.40-1.1.mga9.tainted
lib(64)graphicsmagickwand2-1.3.40-1.1.mga9.tainted
perl-Graphics-Magick-1.3.40-1.1.mga9.tainted

from SRPM:
graphicsmagick-1.3.40-1.1.mga9.tainted.src.rpm

Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs
Source RPM: graphicsmagick => graphicsmagick-1.3.40-1.mga9.src.rpm, graphicsmagick-1.3.40-1.mga9.tainted.src.rpm
Version: Cauldron => 9
Status comment: Patch available from upstream => (none)
Whiteboard: MGA9TOO => (none)

Comment 3 Nicolas Salguero 2025-04-04 17:09:28 CEST
openSUSE has issued an advisory on April 3:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/
message/24QCG7UCRKCAUVWHKRASS2RHMWXRXGZ2/

Whiteboard: (none) => MGA9TOO
Version: 9 => Cauldron
Assignee: qa-bugs => nicolas.salguero
CVE: CVE-2025-27795 => CVE-2025-27795, CVE-2025-27796
Summary: graphicsmagick new security issue CVE-2025-27795 => graphicsmagick new security issues CVE-2025-2779[56]

Comment 4 Nicolas Salguero 2025-04-11 09:07:51 CEST
After verification, CVE-2025-27796 only affected Cauldron.

CVE: CVE-2025-27795, CVE-2025-27796 => CVE-2025-27795
Version: Cauldron => 9
Assignee: nicolas.salguero => qa-bugs
Whiteboard: MGA9TOO => (none)

Comment 5 Herman Viaene 2025-04-11 13:52:37 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
First installed the core versions and followed the wiki as in bug 30211, with the same remark as in bug 28088
$ gm convert D053.jpg D053.tiff
gm convert: D053.tiff: Invalid tag "Predictor" (not supported by codec). (_TIFFVGetField).
but the resulting tiff image is OK, so no regression.
Test includes the perl test.
Continuing for the tainted versions.

CC: (none) => herman.viaene

Comment 6 Herman Viaene 2025-04-11 14:11:38 CEST
Installed tainted without problems.
Deleted all test results from core test above and rerun all commands. All results OK.

Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-04-12 01:10:30 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-04-12 03:29:45 CEST

Keywords: (none) => advisory

Comment 8 Mageia Robot 2025-04-12 06:24:45 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0132.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.