Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61860

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.

A flaw was found in ImageMagick. This vulnerability, a use-after-free, occurs when the freetype library fails to initialize, causing the software to continue processing with freed memory. A remote attacker could exploit this during image processing, leading to a denial of service (DoS) condition, which would make the service unavailable to legitimate users.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. If font rendering via FreeType is not needed, the TTF and OTF coders can be disabled in ImageMagick's policy.xml: <policy domain="coder" rights="none" pattern="{TTF,OTF}"/>. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2500897ImageMagick: ImageMagick: Denial of Service via use-after-free during freetype initialization

EPSS

Процентиль: 13%
0.00222
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.

CVSS3: 3.7
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.

CVSS3: 3.7
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vu ...

CVSS3: 3.7
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 13%
0.00222
Низкий

3.7 Low

CVSS3