Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56364

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.13+dfsg1-1package
imagemagicknot-affectedbookwormpackage
imagemagicknot-affectedbullseyepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp59-x883-77qv

  • Introduced after: https://github.com/ImageMagick/ImageMagick/commit/5a2575faca105cecbf44bc70f7f8a177f6c4f674 (7.0.1-0)

  • Fixed by [1/2]: https://github.com/ImageMagick/ImageMagick/commit/951f6b0940224afc469f6a72503d6e011c688d02 (7.1.2-13)

  • Fixed by [2/2]: https://github.com/ImageMagick/ImageMagick/commit/5fd4e5ad05a986b00e1519fa308ca3c5cf3d09d8 (7.1.2-14)

  • ImageMagick function LoadOpenCLDeviceBenchmark not present in ImageMagick6

EPSS

Процентиль: 7%
0.00169
Низкий

Связанные уязвимости

CVSS3: 1.9
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
redhat
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
nvd
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
redos
7 дней назад

Уязвимость ImageMagick7

CVSS3: 1.9
github
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

EPSS

Процентиль: 7%
0.00169
Низкий