Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56364

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 1.9
EPSS Низкий

Описание

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

A Denial of Service (DoS) vulnerability exists in ImageMagick. An attacker with write access to the OpenCL cache directory can exhaust system memory and crash the application by placing a maliciously crafted file.

Отчет

This vulnerability in ImageMagick is of Low impact. It requires an attacker to have local write access to the OpenCL cache directory and for OpenCL to be enabled. Under these conditions, a specially crafted XML file can cause a memory leak, leading to resource exhaustion and a denial of service over extended periods.

Меры по смягчению последствий

To mitigate this, restrict write access to the OpenCL cache directory to prevent unauthorized or malformed files from being introduced. Additionally, configure process-level memory limits (using mechanisms like ulimit, cgroups, or systemd directives) for ImageMagick to contain potential memory exhaustion and safeguard overall system stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickUnder investigation
Red Hat Enterprise Linux 7ImageMagickUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2495437Magick.NET-Q8-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x86: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-arm64: Magick.NET-Q16-x86: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-HDRI-OpenMP-x64: Magick.NET-Q16-HDRI-OpenMP-arm64: Magick.NET-Q8-AnyCPU: Magick.NET-Q16-AnyCPU: Magick.NET-Q16-HDRI-AnyCPU: ImageMagick: Denial of Service via memory leak in OpenCL device profile XML parsing

EPSS

Процентиль: 5%
0.00154
Низкий

1.9 Low

CVSS3

Связанные уязвимости

CVSS3: 1.9
ubuntu
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
nvd
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.

CVSS3: 1.9
debian
3 месяца назад

ImageMagick before 7.1.2-13 contains a memory leak vulnerability in Lo ...

CVSS3: 1.9
redos
около 2 месяцев назад

Уязвимость ImageMagick

CVSS3: 1.9
redos
около 2 месяцев назад

Уязвимость ImageMagick7

EPSS

Процентиль: 5%
0.00154
Низкий

1.9 Low

CVSS3