Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing images. A flaw in its 'connected-components' feature can cause the program to enter an infinite loop when it receives specifically malformed or invalid arguments. This can lead to a denial-of-service condition, where the application becomes unresponsive and consumes excessive system resources, potentially impacting business operations that rely on automated image processing.
Technical details
A vulnerability exists in ImageMagick's connected-components processing where invalid arguments can trigger an infinite loop (CWE-835). This results in uncontrolled resource consumption (CWE-400), leading to a denial-of-service (DoS) condition. The attack vector is local and requires user interaction, with a high attack complexity as specified by the CVSS metrics. The issue affects various Magick.NET distributions and has been addressed in version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-x86 < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
- ImageMagick,versions: Magick.NET-Q8-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-x86 < 14.15.0
Timeline
- 2026-06-26: disclosed
- 2026-06-26: patched: Magick.NET 14.15.0 released
- 2026-07-24: advisory