Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61465

Опубликовано: 11 июл. 2026
Источник: debian

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package
imagemagickno-dsatrixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/dd0dedbecff931e93c4e72a57f7108bb13f76cf7 (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bcf10763277cdf0f61cf85e786575ae8665f13b (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/1f57c1bdfc1d5e71e4cbd464cca0a569f7fd0733 (6.9.13-51)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/a3201b8c08ad271458bafbd91f7eb4e9976e7399 (6.9.13-51)

Связанные уязвимости

CVSS3: 3.3
ubuntu
23 дня назад

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

CVSS3: 5.5
redhat
23 дня назад

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

CVSS3: 3.3
nvd
23 дня назад

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

CVSS3: 3.3
github
23 дня назад

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to allocate more memory than permitted by the configured policy, resulting in a denial of service.

suse-cvrf
14 дней назад

Security update for ImageMagick