Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25796

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in ReadSTEGANOImage() (coders/stegano.c), the watermark Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, an open-source software for image manipulation. This vulnerability is a memory leak that occurs when processing certain image objects. An attacker can exploit this flaw to repeatedly trigger the memory leak, which can lead to a Denial of Service (DoS) by consuming excessive system memory and making the application unavailable.

Отчет

This MODERATE impact vulnerability in ImageMagick involves a memory leak when processing certain image files due to unfreed objects in the ReadSTEGANOImage() function. This flaw can lead to a denial of service by exhausting system memory. Red Hat Enterprise Linux and community projects utilizing ImageMagick are affected.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or maliciously crafted image files with ImageMagick. If ImageMagick is used in a server-side application or service that handles external input, consider implementing resource limits for the ImageMagick process to prevent excessive memory consumption, or run the process within a sandboxed environment to contain potential denial of service attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2442112ImageMagick: ImageMagick: Denial of Service Vulnerability

EPSS

Процентиль: 17%
0.00055
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
github
около 1 месяца назад

ImageMagick has memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths

suse-cvrf
19 дней назад

Security update for ImageMagick

EPSS

Процентиль: 17%
0.00055
Низкий

5.3 Medium

CVSS3