Executive brief
ImageMagick is a widely used open-source tool for processing and editing digital images. A security flaw has been identified where a specially crafted image file can cause the software to crash or potentially allow unauthorized access to data. This could lead to service disruptions or the exposure of sensitive information on systems that use ImageMagick to process user-uploaded images.
Technical details
An integer overflow vulnerability exists in the DIB (Device Independent Bitmap) coder component of ImageMagick. The flaw occurs during the processing of DIB files, where improper calculation of buffer sizes leads to out-of-bounds (OOB) read or write operations. An attacker can exploit this by providing a maliciously crafted image file. While the attack complexity is rated as high (likely requiring specific memory layouts or conditions), successful exploitation can result in a loss of confidentiality, integrity, and availability. The issue is resolved in versions 7.1.2-16 and 6.9.13-41.
Affected products
- ImageMagick ImageMagick < 7.1.2-16, < 6.9.13-41
- Red Hat Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-03-09: advisory: GitHub Security Advisory published
- 2026-03-10: disclosed: CVE-2026-28693 published to NVD
- 2026-04-06: patched: Red Hat released security updates (RHSA-2026:6713)
References
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76
- https://access.redhat.com/errata/RHSA-2026:6713
- https://access.redhat.com/security/cve/CVE-2026-28693
- https://bugzilla.redhat.com/show_bug.cgi?id=2445888
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json