Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56364

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 1.9

Описание

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

A Denial of Service (DoS) vulnerability exists in ImageMagick. An attacker with write access to the OpenCL cache directory can exhaust system memory and crash the application by placing a maliciously crafted file.

Отчет

This vulnerability in ImageMagick is of Low impact. It requires an attacker to have local write access to the OpenCL cache directory and for OpenCL to be enabled. Under these conditions, a specially crafted XML file can cause a memory leak, leading to resource exhaustion and a denial of service over extended periods.

Меры по смягчению последствий

To mitigate this, restrict write access to the OpenCL cache directory to prevent unauthorized or malformed files from being introduced. Additionally, configure process-level memory limits (using mechanisms like ulimit, cgroups, or systemd directives) for ImageMagick to contain potential memory exhaustion and safeguard overall system stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickUnder investigation
Red Hat Enterprise Linux 7ImageMagickUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2495437Magick.NET-Q8-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x86: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-arm64: Magick.NET-Q16-x86: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-HDRI-OpenMP-x64: Magick.NET-Q16-HDRI-OpenMP-arm64: Magick.NET-Q8-AnyCPU: Magick.NET-Q16-AnyCPU: Magick.NET-Q16-HDRI-AnyCPU: ImageMagick: Denial of Service via memory leak in OpenCL device profile XML parsing

1.9 Low

CVSS3

Связанные уязвимости

CVSS3: 1.9
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
nvd
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
debian
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in Lo ...

CVSS3: 1.9
redos
7 дней назад

Уязвимость ImageMagick7

CVSS3: 1.9
github
около 1 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

1.9 Low

CVSS3