CVE-2026-56368 PUBLISHED

ImageMagick - Memory Leak in Raw Pixel Data Coders

Assigner: VulnCheck
Reserved: 21.06.2026 Published: 24.06.2026 Updated: 24.06.2026

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor ImageMagick
Product ImageMagick
Versions Default: unaffected
  • affected from 0 to 7.1.2-15 (excl.)
  • Version 7.1.2-15 is unaffected
Vendor ImageMagick
Product ImageMagick
Versions Default: unaffected
  • affected from 0 to 6.9.13-40 (excl.)
  • Version 6.9.13-40 is unaffected

Credits

  • ylwango613 reporter

References

Problem Types

  • Missing Release of Memory after Effective Lifetime CWE