Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56376

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 3.7

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

A flaw was found in ImageMagick. Remote attackers can exploit a heap use-after-free vulnerability in the meta coder by processing specially crafted image files. This can lead to a denial of service.

Отчет

This ImageMagick flaw is rated as Low impact. A heap use-after-free vulnerability in the meta coder can lead to a denial of service when processing specially crafted image files. The impact is limited to availability, and the attack requires specific conditions, making successful exploitation less probable in typical Red Hat deployments unless processing untrusted images.

Меры по смягчению последствий

Since this vulnerability is isolated entirely within ImageMagick's meta coder, the mitigation is to disable that specific coder.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2491704ImageMagick: ImageMagick: Denial of Service via heap use-after-free vulnerability

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

CVSS3: 3.7
nvd
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

CVSS3: 3.7
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-fr ...

CVSS3: 3.7
redos
около 1 месяца назад

Уязвимость ImageMagick7

CVSS3: 3.7
redos
около 1 месяца назад

Уязвимость ImageMagick

3.7 Low

CVSS3