Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26983

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 5.3

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid <map> element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, a software suite for editing and manipulating digital images. A remote attacker could exploit this vulnerability by providing a specially crafted image containing an invalid <map> element to the Magick Scripting Language (MSL) interpreter. This flaw causes a use-after-free, leading to an application crash and resulting in a Denial of Service (DoS).

Отчет

MODERATE: This flaw in ImageMagick allows a use-after-free vulnerability when processing a specially crafted MSL <map> element. An attacker could provide a malicious image file, leading to a denial of service due to application crashes. This affects systems where ImageMagick is used to process untrusted image files.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or maliciously crafted image files with ImageMagick. If ImageMagick is used in a service, restrict access to trusted sources and ensure input validation is in place to prevent the processing of arbitrary or malformed MSL files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2442134ImageMagick: ImageMagick: Denial of Service via invalid MSL map element processing

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
github
около 1 месяца назад

ImageMagick: Invalid MSL <map> can result in a use after free

suse-cvrf
19 дней назад

Security update for ImageMagick

5.3 Medium

CVSS3