Junglewise Threat Intelligence

CVE-2026-25794: ImageMagick heap overflow in WriteUHDRImage

CVE-2026-25794 · Severity: high · CVSS 8.2 · Published 2026-02-24

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-OpenMP-x86 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Red Hat Enterprise Linux 6, Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, Red Hat, ImageMagick.

Executive brief

ImageMagick is a widely used open-source tool for creating, editing, and converting digital images. A vulnerability in how it handles Ultra High Dynamic Range (UHDR) images could allow an attacker to crash the software or potentially execute unauthorized code by providing a specially crafted image with very large dimensions. This could lead to service disruptions or unauthorized access to systems that automatically process user-uploaded images.

Technical details

An integer overflow vulnerability exists in ImageMagick's `WriteUHDRImage` function within `coders/uhdr.c`. The software uses 32-bit signed integer arithmetic to calculate the pixel buffer size; when processing images with extremely large dimensions, this multiplication overflows, resulting in an undersized heap allocation. Subsequent write operations then exceed the buffer boundaries, leading to a heap-based buffer overflow. A remote attacker can exploit this by providing a malicious UHDR image, potentially causing a denial-of-service (crash) or arbitrary code execution. The issue is fixed in version 7.1.2-15.

Affected products

  • ImageMagick ImageMagick < 7.1.2-15
  • Red Hat Enterprise Linux 6 affected

Timeline

  • 2026-02-23: disclosed: Initial disclosure by GitHub/ImageMagick
  • 2026-02-23: patched: Version 7.1.2-15 released with fix
  • 2026-02-24: advisory: NVD and Red Hat advisories published

References

Related threats