Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability was found in its image sampling operation that could allow a specially crafted image to crash the application. This could lead to a denial-of-service, impacting the availability of services that rely on ImageMagick for automated image processing.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in ImageMagick's '-sample' operation. The flaw is triggered when a specific offset is provided through the 'sample:offset' define, leading the application to read memory outside of the intended buffer. This is a local attack that requires user interaction, such as a user or automated process attempting to process a malicious image file. Successful exploitation can lead to an application crash (Denial of Service). The issue is addressed in ImageMagick version 7.1.2-19 and Magick.NET version 14.12.0.
Affected products
- ImageMagick ImageMagick < 7.1.2-19
- dlemstra Magick.NET < 14.12.0
Timeline
- 2026-04-13: disclosed
- 2026-04-13: patched
- 2026-04-14: advisory
References
- https://api.github.com/users/shitianyu-2004
- https://github.com/shitianyu-2004
- https://api.github.com/users/shitianyu-2004/gists%7B/gist_id%7D
- https://api.github.com/users/shitianyu-2004/repos
- https://avatars.githubusercontent.com/u/238960946?v=4
- https://api.github.com/users/shitianyu-2004/events%7B/privacy%7D