Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56368

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

A flaw was found in ImageMagick. This memory leak vulnerability exists in multiple coders that write raw pixel data, where allocated objects are not properly freed. A remote attacker can exploit this by processing specially crafted images, leading to memory exhaustion and a denial of service.

Отчет

A memory leak exists in ImageMagick's raw pixel data coders. Processing specially crafted, untrusted images can exhaust system memory and cause a Denial of Service (DoS).

Меры по смягчению последствий

Modify the ImageMagick security policy file (policy.xml, typically located in /etc/ImageMagick-7/ or /etc/ImageMagick-6/) to disable the processing of RAW pixel data formats.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2492145Imagemagick: ImageMagick - Memory Leak in Raw Pixel Data Coders

EPSS

Процентиль: 18%
0.0026
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

CVSS3: 3.7
nvd
около 1 месяца назад

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

CVSS3: 3.7
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in mu ...

CVSS3: 3.7
github
5 месяцев назад

ImageMagick: Memory Leak in multiple coders that write raw pixel data

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость консольного графического редактора ImageMagick, связанная с отсутствием освобождения памяти после эффективного срока службы, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 18%
0.0026
Низкий

3.7 Low

CVSS3