Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61871

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak in the ICON decoder by providing a specially crafted ICON file. When the file is processed, a memory allocation failure occurs, leading to memory exhaustion. This can result in a denial of service (DoS), making the affected system or application unavailable.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. The ICON coder can be disabled in ImageMagick's policy.xml if not needed: <policy domain="coder" rights="none" pattern="ICON"/>. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2500909ImageMagick: ImageMagick: Denial of Service via memory leak in ICON decoder

EPSS

Процентиль: 14%
0.00232
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

CVSS3: 3.7
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

CVSS3: 3.7
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...

CVSS3: 3.7
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 14%
0.00232
Низкий

3.7 Low

CVSS3