Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing images. A vulnerability in its subimage-search feature allows a specially crafted image to trigger an infinite loop, which can cause the application to stop responding. This could lead to a denial-of-service condition, impacting the availability of systems that process user-supplied images.
Technical details
A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in ImageMagick's subimage-search operation. The flaw is triggered when the software processes a specially crafted image, leading to an infinite loop that consumes system resources. The attack vector is local and requires user interaction, such as a user opening or processing a malicious image file. This results in a high impact on availability (Denial of Service) but does not affect confidentiality or integrity. The issue is addressed in Magick.NET version 14.14.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.14.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-arm64 < 14.14.0
- ImageMagick Magick.NET-Q16-x64 < 14.14.0
- ImageMagick Magick.NET-Q16-x86 < 14.14.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.14.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.14.0
- ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.14.0
- ImageMagick Magick.NET-Q8-arm64 < 14.14.0
- ImageMagick Magick.NET-Q8-x64 < 14.14.0
- ImageMagick Magick.NET-Q8-x86 < 14.14.0
Timeline
- 2026-05-30: disclosed
- 2026-06-10: advisory: NVD publication date
- 2026-06-25: advisory: GitHub Advisory published