Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56376

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

A flaw was found in ImageMagick. Remote attackers can exploit a heap use-after-free vulnerability in the meta coder by processing specially crafted image files. This can lead to a denial of service.

Отчет

This ImageMagick flaw is rated as Low impact. A heap use-after-free vulnerability in the meta coder can lead to a denial of service when processing specially crafted image files. The impact is limited to availability, and the attack requires specific conditions, making successful exploitation less probable in typical Red Hat deployments unless processing untrusted images.

Меры по смягчению последствий

Since this vulnerability is isolated entirely within ImageMagick's meta coder, the mitigation is to disable that specific coder.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2491704ImageMagick: ImageMagick: Denial of Service via heap use-after-free vulnerability

EPSS

Процентиль: 25%
0.0032
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

CVSS3: 3.7
nvd
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

CVSS3: 3.7
debian
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-fr ...

CVSS3: 3.7
redos
3 месяца назад

Уязвимость ImageMagick

CVSS3: 3.7
github
3 месяца назад

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.

EPSS

Процентиль: 25%
0.0032
Низкий

3.7 Low

CVSS3