Executive brief
ImageMagick is a widely used software suite for editing and processing digital images. A vulnerability in how it handles hardware acceleration settings could allow a user with high-level system access to cause the software to consume excessive memory. This could eventually lead to a system slowdown or a service outage, though it requires specific local access to exploit.
Technical details
A memory leak (CWE-401) exists in MagickCore/opencl.c within the LoadOpenCLDeviceBenchmark() function. The vulnerability is triggered when the parser encounters malformed OpenCL device profile XML files containing unclosed <device> elements. While the function allocates memory for string members such as platform_name and vendor_name, it only releases them if a proper closing tag is parsed. An attacker with write access to the OpenCL cache directory (~/.cache/ImageMagick/) can plant a malicious XML file to cause repeated memory leaks during initialization, leading to a denial of service. This issue is resolved in version 7.1.2-13.
Affected products
- ImageMagick ImageMagick < 7.1.2-13
Timeline
- 2026-01-19: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date