Junglewise Threat Intelligence

CVE-2026-56364: ImageMagick memory leak in LoadOpenCLDeviceBenchmark

CVE-2026-56364 · Severity: low · CVSS 3.1 · Published 2026-06-30

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-OpenMP-x86 (NuGet), ImageMagick, Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a widely used software suite for editing and processing digital images. A vulnerability in how it handles hardware acceleration settings could allow a user with high-level system access to cause the software to consume excessive memory. This could eventually lead to a system slowdown or a service outage, though it requires specific local access to exploit.

Technical details

A memory leak (CWE-401) exists in MagickCore/opencl.c within the LoadOpenCLDeviceBenchmark() function. The vulnerability is triggered when the parser encounters malformed OpenCL device profile XML files containing unclosed <device> elements. While the function allocates memory for string members such as platform_name and vendor_name, it only releases them if a proper closing tag is parsed. An attacker with write access to the OpenCL cache directory (~/.cache/ImageMagick/) can plant a malicious XML file to cause repeated memory leaks during initialization, leading to a denial of service. This issue is resolved in version 7.1.2-13.

Affected products

  • ImageMagick ImageMagick < 7.1.2-13

Timeline

  • 2026-01-19: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References

Related threats