Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56365

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak vulnerability in the Portable Network Graphics (PNG) encoder when it fails to write Multiple-image Network Graphics (MNG) images. This flaw allows attackers to exhaust memory resources, leading to a denial of service (DoS) condition. This issue is categorized as a memory leak (CWE-401).

Отчет

This Low impact memory leak in ImageMagick's PNG encoder, when processing Multiple-image Network Graphics (MNG) images, could lead to a denial of service. While the flaw can exhaust system memory, it requires an application to process a specially crafted MNG image, limiting the attack surface in typical Red Hat deployments.

Меры по смягчению последствий

To mitigate this use system controls (such as ulimit or container memory limits) to strictly cap the memory available to the ImageMagick process. This prevents a leak from crashing the wider system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2495448Magick.NET-Q16-AnyCPU: Magick.NET-Q16-HDRI-AnyCPU: Magick.NET-Q16-HDRI-OpenMP-arm64: Magick.NET-Q16-HDRI-arm64: Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q16-HDRI-OpenMP-x64: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Denial of Service due to memory leak in PNG encoder when processing MNG images

EPSS

Процентиль: 21%
0.00284
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

CVSS3: 3.7
nvd
около 1 месяца назад

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

CVSS3: 3.7
debian
около 1 месяца назад

ImageMagick before 7.1.2-19 contains a memory leak vulnerability in th ...

CVSS3: 3.7
redos
12 дней назад

Уязвимость ImageMagick

CVSS3: 3.7
redos
12 дней назад

Уязвимость ImageMagick7

EPSS

Процентиль: 21%
0.00284
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2026-56365