Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66011

Опубликовано: 25 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

A flaw was found in ImageMagick. This memory leak vulnerability occurs when invalid options are provided to the magick command-line interface (CLI). An attacker can exploit this by repeatedly supplying malformed command-line arguments, leading to memory exhaustion and a denial of service (DoS) on the affected system.

Отчет

This vulnerability has a Low impact as it requires local system access and user interaction to exploit. An attacker must repeatedly supply malformed command-line arguments to the magick utility, leading to a memory leak and potential resource exhaustion.

Меры по смягчению последствий

To mitigate this issue, strictly sanitize inputs to prevent invalid CLI options from being passed to ImageMagick. Enforce process memory limits (via cgroups or ulimit) on ImageMagick executions to prevent potential memory exhaustion.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2507302Imagemagick: ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 дней назад

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

CVSS3: 3.3
nvd
7 дней назад

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

CVSS3: 3.3
debian
7 дней назад

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in th ...

CVSS3: 3.3
github
7 дней назад

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

3.3 Low

CVSS3