Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86420

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

A flaw was found in ImageMagick. This vulnerability occurs when the software fails to correctly manage its memory budget during certain image processing operations. Repeatedly triggering these failures can lead to the exhaustion of the process's memory, causing the application to become unresponsive and resulting in a denial of service.

Отчет

Red Hat has evaluated this issue and determined it is of Low severity. No fix is currently planned for the affected Red Hat Enterprise Linux Extended Life Support versions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2529441ImageMagick: ImageMagick: Denial of Service due to memory budget exhaustion

EPSS

Процентиль: 25%
0.00321
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
7 дней назад

(ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the ...)

CVSS3: 3.7
nvd
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

CVSS3: 3.7
debian
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the ...

CVSS3: 3.7
github
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

EPSS

Процентиль: 25%
0.00321
Низкий

3.7 Low

CVSS3