Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23952

Опубликовано: 22 янв. 2026
Источник: redhat
CVSS3: 6.5

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.

A flaw was found in ImageMagick. A remote attacker could exploit a NULL pointer dereference vulnerability in the Magick Scripting Language (MSL) parser. This occurs when processing tags before images are loaded. Successful exploitation can lead to a Denial of Service (DoS) attack, making the software unavailable.

Отчет

This vulnerability is rated Moderate for Red Hat products. A NULL pointer dereference flaw exists in ImageMagick's MSL parser when processing tags before image loading. This could allow an attacker to cause a Denial of Service (DoS) by providing a specially crafted image file. This affects ImageMagick versions 14.10.1 and below, as shipped in various Red Hat products including EPEL and Red Hat Enterprise Linux Extended Life Cycle Support (ELS) releases.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted or specially crafted MSL (Magick Scripting Language) files with ImageMagick. Restricting the sources of MSL files and ensuring that ImageMagick only processes trusted input can reduce the risk of exploitation. If ImageMagick is used in an automated pipeline, consider implementing sandboxing mechanisms to limit the impact of potential denial-of-service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2431905ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.

CVSS3: 6.5
nvd
2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.

CVSS3: 6.5
debian
2 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 6.5
github
2 месяца назад

ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load

suse-cvrf
около 1 месяца назад

Security update for ImageMagick

6.5 Medium

CVSS3