Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86423

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).

A flaw was found in ImageMagick, specifically within the PerlMagick component's GetList method. A local attacker could exploit a heap-use-after-free vulnerability by crafting a malicious call to this method. This could lead to a system crash, resulting in a denial of service.

Отчет

Red Hat has evaluated this issue and determined it is of Low severity. No fix is currently planned for the affected RHEL Extended Life Support versions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2529436ImageMagick: ImageMagick: Denial of service via heap-use-after-free in PerlMagick's GetList method

EPSS

Процентиль: 2%
0.00113
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 дней назад

(ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)

CVSS3: 3.3
nvd
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).

CVSS3: 3.3
debian
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...

CVSS3: 3.3
github
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).

EPSS

Процентиль: 2%
0.00113
Низкий

3.3 Low

CVSS3