Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61868

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak in the YUV decoder when processing a specially crafted image file. Repeatedly triggering this flaw can lead to resource exhaustion, resulting in a denial of service for the application.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. The YUV coder can be disabled in ImageMagick's policy.xml if not needed: <policy domain="coder" rights="none" pattern="YUV"/>. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2500925ImageMagick: ImageMagick: Denial of Service due to memory leak in YUV decoder

EPSS

Процентиль: 13%
0.00222
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

CVSS3: 3.7
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

CVSS3: 3.7
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memo ...

CVSS3: 3.7
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 13%
0.00222
Низкий

3.7 Low

CVSS3