Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61869

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 2.9
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

A flaw was found in ImageMagick. A memory leak in the Magick Image File Format (MIFF) encoder can occur when the software attempts to process an image and a memory allocation fails. This vulnerability allows an attacker to cause a denial of service (DoS) by exhausting system resources.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. The MIFF coder can be disabled in ImageMagick's policy.xml if not needed: <policy domain="coder" rights="none" pattern="MIFF"/>. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2500928ImageMagick: ImageMagick: Denial of Service via memory leak in MIFF encoder

EPSS

Процентиль: 1%
0.00102
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

CVSS3: 2.9
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

CVSS3: 2.9
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...

CVSS3: 2.9
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 1%
0.00102
Низкий

2.9 Low

CVSS3