Executive brief
ImageMagick is a widely used open-source tool for creating, editing, and converting digital images. A security flaw in its distributed pixel cache service could allow a high-privileged user to crash the server process. This could lead to a denial-of-service, impacting the availability of image processing operations within an organization's workflow.
Technical details
A heap-based buffer overflow (CWE-122) exists in ImageMagick's distributed pixel cache server component. The vulnerability is triggered when an attacker connects to the 'magick -distribute-cache' service and performs operations that result in a heap buffer overwrite. Exploitation requires local access, high privileges, and faces high attack complexity. Successful exploitation primarily impacts system availability by causing the server process to crash. The issue is resolved in ImageMagick versions 6.9.13-48 and 7.1.2-23.
Affected products
- ImageMagick ImageMagick < 6.9.13-48, < 7.1.2-23
Timeline
- 2026-05-18: advisory: GitHub advisory published by maintainers
- 2026-06-10: disclosed: CVE published to NVD