Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56364

Опубликовано: 30 июн. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.13+dfsg1-1package
imagemagicknot-affectedbookwormpackage
imagemagicknot-affectedbullseyepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp59-x883-77qv

  • Introduced after: https://github.com/ImageMagick/ImageMagick/commit/5a2575faca105cecbf44bc70f7f8a177f6c4f674 (7.0.1-0)

  • Fixed by [1/2]: https://github.com/ImageMagick/ImageMagick/commit/951f6b0940224afc469f6a72503d6e011c688d02 (7.1.2-13)

  • Fixed by [2/2]: https://github.com/ImageMagick/ImageMagick/commit/5fd4e5ad05a986b00e1519fa308ca3c5cf3d09d8 (7.1.2-14)

  • ImageMagick function LoadOpenCLDeviceBenchmark not present in ImageMagick6

EPSS

Процентиль: 5%
0.00154
Низкий

Связанные уязвимости

CVSS3: 1.9
ubuntu
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
redhat
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
nvd
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
redos
около 2 месяцев назад

Уязвимость ImageMagick

CVSS3: 1.9
redos
около 2 месяцев назад

Уязвимость ImageMagick7

EPSS

Процентиль: 5%
0.00154
Низкий