Junglewise Threat Intelligence

CVE-2026-56362: ImageMagick heap overflow in GetPixelIndex

CVE-2026-56362 · Severity: low · CVSS 3.3 · Published 2026-07-08

Technologies: ImageMagick, Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-OpenMP-x86 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: ImageMagick, NuGet.

Executive brief

ImageMagick is a widely used software suite for displaying, converting, and editing images. A vulnerability in how it manages image memory could allow an attacker with high-level access to cause a minor information leak or a service crash. This occurs when the software fails to properly synchronize image metadata with its internal memory storage during specific failure conditions.

Technical details

A heap-buffer-overflow read vulnerability exists in ImageMagick's GetPixelIndex function. The root cause is located in OpenPixelCache, which updates image channel metadata before successfully completing pixel cache memory allocation. If an attacker can trigger simultaneous memory and disk allocation failures, the resulting metadata desynchronization leads to an out-of-bounds read (CWE-125) when GetPixelIndex is subsequently called. Exploitation requires high privileges and specific environmental conditions (high attack complexity), potentially allowing for limited information disclosure or a denial-of-service state. The issue is patched in versions 7.1.2-15 and 6.9.13-40.

Affected products

  • ImageMagick ImageMagick < 7.1.2-15, < 6.9.13-40

Timeline

  • 2026-02-23: advisory: GitHub Security Advisory published
  • 2026-07-08: disclosed: NVD publication date

References

Related threats