Commit 64645a7e7 for imagemagick.org

commit 64645a7e72cf597de471dce016f3496c1e29c17a
Author: Cristy <urban-warrior@imagemagick.org>
Date:   Wed Sep 30 14:49:07 2026 -0400

    https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j657-rmv3-4m94

diff --git a/coders/msl.c b/coders/msl.c
index 71cc06806..7caeec16b 100644
--- a/coders/msl.c
+++ b/coders/msl.c
@@ -281,8 +281,8 @@ static void MSLPopImage(MSLInfo *msl_info)
   if (msl_info->number_groups != 0)
     return;
   if (msl_info->image[msl_info->n] != (Image *) NULL)
-    msl_info->image[msl_info->n]=DestroyImage(msl_info->image[msl_info->n]);
-  msl_info->attributes[msl_info->n]=DestroyImage(
+    msl_info->image[msl_info->n]=DestroyImageList(msl_info->image[msl_info->n]);
+  msl_info->attributes[msl_info->n]=DestroyImageList(
     msl_info->attributes[msl_info->n]);
   msl_info->draw_info[msl_info->n]=DestroyDrawInfo(
     msl_info->draw_info[msl_info->n]);
@@ -452,7 +452,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           (void) SetPixelChannelMask(msl_info->image[n],channel_mask);
           if (noise_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=noise_image;
           break;
         }
@@ -845,7 +845,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (append_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=append_image;
           break;
         }
@@ -869,7 +869,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           if (new_image == (Image *) NULL)
             break;

-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=new_image;
           break;
         }
@@ -971,7 +971,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           (void) SetPixelChannelMask(msl_info->image[n],channel_mask);
           if (blur_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=blur_image;
           break;
         }
@@ -1081,7 +1081,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->image[n]->compose,msl_info->exception);
           if (border_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=border_image;
           break;
         }
@@ -1160,7 +1160,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (colorize_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=colorize_image;
           break;
         }
@@ -1232,7 +1232,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         break;
         }
@@ -1337,7 +1337,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (chop_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=chop_image;
           break;
         }
@@ -1752,7 +1752,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
                                compose,MagickTrue,x,y,exception);
                          }
                       if (rotate_image != (Image *) NULL)
-                        rotate_image=DestroyImage(rotate_image);
+                        rotate_image=DestroyImageList(rotate_image);
                       break;
                     }
                   ThrowMSLException(OptionError,"UnrecognizedAttribute",
@@ -1813,10 +1813,10 @@ static void MSLStartElement(void *context,const xmlChar *tag,
                 composite_image->rows)/2;
               CompositeImage(image,rotate_image,compose,MagickTrue,geometry.x,
                 geometry.y,exception);
-              rotate_image=DestroyImage(rotate_image);
+              rotate_image=DestroyImageList(rotate_image);
             }
           (void) SetImageChannelMask(image,channel_mask);
-          composite_image=DestroyImage(composite_image);
+          composite_image=DestroyImageList(composite_image);
           break;
         }
       if (LocaleCompare((const char *) tag,"contrast") == 0)
@@ -1971,7 +1971,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (crop_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=crop_image;
           break;
         }
@@ -2057,7 +2057,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (despeckle_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=despeckle_image;
           break;
         }
@@ -2508,7 +2508,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (edge_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=edge_image;
           break;
         }
@@ -2587,7 +2587,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry_info.sigma,msl_info->exception);
           if (emboss_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=emboss_image;
           break;
         }
@@ -2619,7 +2619,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (enhance_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=enhance_image;
           break;
         }
@@ -2674,7 +2674,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (newImage == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=newImage;
           break;
         }
@@ -2707,7 +2707,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (flip_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=flip_image;
           break;
         }
@@ -2739,7 +2739,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (flop_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=flop_image;
           break;
         }
@@ -2887,7 +2887,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->image[n]->compose,msl_info->exception);
           if (frame_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=frame_image;
           break;
         }
@@ -3199,7 +3199,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->image[n]->interpolate,msl_info->exception);
           if (implode_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=implode_image;
           break;
         }
@@ -3311,7 +3311,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (magnify_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=magnify_image;
           break;
         }
@@ -3400,7 +3400,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             {
               (void) RemapImages(quantize_info,msl_info->image[n],
                 affinity_image,exception);
-              affinity_image=DestroyImage(affinity_image);
+              affinity_image=DestroyImageList(affinity_image);
             }
           quantize_info=DestroyQuantizeInfo(quantize_info);
           break;
@@ -3608,7 +3608,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (median_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=median_image;
           break;
         }
@@ -3640,7 +3640,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (minify_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=minify_image;
           break;
         }
@@ -3966,7 +3966,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry_info.sigma,msl_info->exception);
           if (paint_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=paint_image;
           break;
         }
@@ -4185,7 +4185,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
                     GetStringInfoLength(profile),exception);
                 profile_name=GetNextImageProfile(profile_image);
               }
-              profile_image=DestroyImage(profile_image);
+              profile_image=DestroyImageList(profile_image);
             }
             break;
           }
@@ -4905,7 +4905,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (paint_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=paint_image;
           break;
         }
@@ -5128,7 +5128,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           msl_info->image[n]->filter,msl_info->exception);
         if (resample_image == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=resample_image;
       }
       break;
@@ -5227,7 +5227,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry.height,filter,msl_info->exception);
           if (resize_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=resize_image;
           break;
         }
@@ -5307,7 +5307,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (roll_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=roll_image;
           break;
         }
@@ -5385,7 +5385,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
         newImage=RollImage(msl_info->image[n], x, y, msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         }

@@ -5454,7 +5454,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (rotate_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=rotate_image;
           break;
         }
@@ -5509,7 +5509,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
         newImage=RotateImage(msl_info->image[n], degrees, msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         }

@@ -5594,7 +5594,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry.height,msl_info->exception);
           if (sample_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=sample_image;
           break;
         }
@@ -5671,7 +5671,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry.height,msl_info->exception);
           if (scale_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=scale_image;
           break;
         }
@@ -6024,7 +6024,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry_info.sigma,msl_info->exception);
           if (shade_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=shade_image;
           break;
         }
@@ -6126,7 +6126,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             (ssize_t) ceil(geometry_info.psi-0.5),msl_info->exception);
           if (shadow_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=shadow_image;
           break;
         }
@@ -6198,7 +6198,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         break;
         }
@@ -6286,7 +6286,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         }

@@ -6380,7 +6380,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             geometry_info.sigma,msl_info->exception);
           if (shear_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=shear_image;
           break;
         }
@@ -6531,7 +6531,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->exception);
           if (spread_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=spread_image;
           break;
         }
@@ -6597,7 +6597,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
         newImage=SteganoImage(msl_info->image[n], watermark, msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         break;
         } else
@@ -6664,7 +6664,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
         newImage=StereoImage(msl_info->image[n], stereoImage, msl_info->exception);
         if (newImage == (Image *) NULL)
           break;
-        msl_info->image[n]=DestroyImage(msl_info->image[n]);
+        msl_info->image[n]=DestroyImageList(msl_info->image[n]);
         msl_info->image[n]=newImage;
         break;
         } else
@@ -6826,7 +6826,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
             msl_info->image[n]->interpolate,msl_info->exception);
           if (swirl_image == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=swirl_image;
           break;
         }
@@ -6915,7 +6915,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
               }
             }
           (void) TextureImage(msl_info->image[n],texture_image,exception);
-          texture_image=DestroyImage(texture_image);
+          texture_image=DestroyImageList(texture_image);
           break;
         }
       else if (LocaleCompare((const char *) tag,"threshold") == 0)
@@ -7034,7 +7034,7 @@ static void MSLStartElement(void *context,const xmlChar *tag,
           newImage=CropImage(msl_info->image[n],&rectInfo, msl_info->exception);
           if (newImage == (Image *) NULL)
             break;
-          msl_info->image[n]=DestroyImage(msl_info->image[n]);
+          msl_info->image[n]=DestroyImageList(msl_info->image[n]);
           msl_info->image[n]=newImage;
           break;
         }
@@ -7174,9 +7174,9 @@ static void MSLEndElement(void *context,const xmlChar *tag)
           while ((i--) && (msl_info->n > 0))
           {
             if (msl_info->image[msl_info->n] != (Image *) NULL)
-              msl_info->image[msl_info->n]=DestroyImage(
+              msl_info->image[msl_info->n]=DestroyImageList(
                 msl_info->image[msl_info->n]);
-            msl_info->attributes[msl_info->n]=DestroyImage(
+            msl_info->attributes[msl_info->n]=DestroyImageList(
               msl_info->attributes[msl_info->n]);
             msl_info->draw_info[msl_info->n]=DestroyDrawInfo(
               msl_info->draw_info[msl_info->n]);
@@ -7357,8 +7357,8 @@ static void DestroyMSLInfo(MSLInfo *msl_info)
   while (msl_info->n >= 0)
   {
     if (msl_info->image[msl_info->n] != (Image *) NULL)
-      msl_info->image[msl_info->n]=DestroyImage(msl_info->image[msl_info->n]);
-    msl_info->attributes[msl_info->n]=DestroyImage(msl_info->attributes[msl_info->n]);
+      msl_info->image[msl_info->n]=DestroyImageList(msl_info->image[msl_info->n]);
+    msl_info->attributes[msl_info->n]=DestroyImageList(msl_info->attributes[msl_info->n]);
     msl_info->draw_info[msl_info->n]=DestroyDrawInfo(msl_info->draw_info[msl_info->n]);
     msl_info->image_info[msl_info->n]=DestroyImageInfo(msl_info->image_info[msl_info->n]);
     msl_info->n--;
@@ -7536,7 +7536,7 @@ static Image *ReadMSLImage(const ImageInfo *image_info,ExceptionInfo *exception)
   image=(Image *) NULL;
   status=ProcessMSLScript(image_info,&image,exception);
   if ((status == MagickFalse) && (image != (Image *) NULL))
-    image=DestroyImage(image);
+    image=DestroyImageList(image);
   return(GetFirstImageInList(image));
 }
 #endif