Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61867

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 2.9

Описание

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak vulnerability within the TIFF encoder. By processing specially crafted TIFF images, an attacker can trigger memory allocation failures, leading to memory exhaustion. This can result in a denial of service (DoS), making the affected system or application unavailable.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. If processing of untrusted input is required, configure ImageMagick's policy.xml to set memory and map resource limits to contain the impact of potential memory leaks. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2500913ImageMagick: ImageMagick: Denial of Service due to memory leak in TIFF encoder

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
nvd
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

CVSS3: 2.9
debian
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...

CVSS3: 2.9
github
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.

2.9 Low

CVSS3