Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25986

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick. A heap buffer overflow vulnerability exists when processing specially crafted YUV 4:2:2 (NoInterlace) images. A remote attacker could exploit this by providing a malicious image, leading to a denial of service (DoS) due to a write beyond the allocated buffer.

Отчет

This MODERATE impact vulnerability in ImageMagick affects Red Hat Enterprise Linux 6 ELS and 7 ELS. A heap buffer overflow occurs when processing specially crafted YUV 4:2:2 images, which could lead to denial of service or potentially arbitrary code execution. Exploitation requires an attacker to provide a malicious image file to a system using ImageMagick.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted YUV 4:2:2 image files with ImageMagick. If ImageMagick is used in automated workflows or server-side applications, consider implementing sandboxing mechanisms to limit the potential impact of processing malicious input. Ensure that ImageMagick instances are not exposed to untrusted input sources without proper validation and isolation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2442111ImageMagick: ImageMagick: Denial of Service via malicious YUV image processing

EPSS

Процентиль: 18%
0.00056
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
github
16 дней назад

ImageMagick has heap buffer overflow in YUV 4:2:2 decoder

suse-cvrf
19 дней назад

Security update for ImageMagick

EPSS

Процентиль: 18%
0.00056
Низкий

5.3 Medium

CVSS3