Executive brief
ImageMagick, a widely used tool for processing and editing digital images, is vulnerable to a flaw that can cause the software to crash. By providing a specially crafted image file, an attacker can trigger a service outage, potentially disrupting automated workflows or web services that rely on this tool for image processing. This issue affects various versions of the software and has been addressed in recent security updates.
Technical details
An uninitialized pointer dereference vulnerability exists in ImageMagick's JBIG decoder due to a missing check on return values (CWE-252, CWE-824). A remote, unauthenticated attacker can exploit this by providing a malformed JBIG image file for processing, leading to an application crash and denial of service (DoS). The vulnerability is reachable over the network if the application processes user-supplied images. Patches are available in ImageMagick versions 7.1.2-16 and 6.9.13-41, and Red Hat has released updates for affected Enterprise Linux distributions.
Affected products
- ImageMagick ImageMagick < 7.1.2-16, < 6.9.13-41
- Red Hat Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-03-09: disclosed: Initial report and GitHub advisory publication
- 2026-03-10: advisory: NVD publication date
- 2026-04-06: patched: Red Hat released security updates (RHSA-2026:6713)
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f
- https://access.redhat.com/errata/RHSA-2026:6713
- https://access.redhat.com/security/cve/CVE-2026-28691
- https://bugzilla.redhat.com/show_bug.cgi?id=2445902
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json