Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-86425

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

A flaw was found in ImageMagick and PerlMagick. An attacker can exploit a heap-use-after-free vulnerability in the Layer method by providing a specially crafted list of images. This can lead to memory corruption and cause a denial of service (DoS) by crashing the application.

Отчет

Red Hat has evaluated this issue and determined it is of Low severity. No fix is currently planned for the affected Red Hat Enterprise Linux Extended Life Support versions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2529445ImageMagick: PerlMagick: ImageMagick: Denial of Service due to heap-use-after-free vulnerability

EPSS

Процентиль: 4%
0.00146
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
7 дней назад

(ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)

CVSS3: 3.3
nvd
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

CVSS3: 3.3
debian
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...

CVSS3: 3.3
github
9 дней назад

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

EPSS

Процентиль: 4%
0.00146
Низкий

3.3 Low

CVSS3