Junglewise Threat Intelligence

CVE-2026-61464: ImageMagick heap buffer overwrite in X11 import

CVE-2026-61464 · Severity: low · CVSS 3.1 · Published 2026-07-15

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick is a popular software suite used for editing and converting digital images. A vulnerability exists when the software attempts to import images from an X11 window system using a specially crafted window title. If exploited, this could cause the application to crash, leading to a denial of service, though it requires high privileges and specific user interaction to execute.

Technical details

A heap-based buffer overflow (CWE-122) exists in ImageMagick's X11 import component. The vulnerability is triggered when the application processes an X11 window with a maliciously crafted title, leading to a heap-based buffer overwrite. Exploitation requires local access, high privileges, and user interaction, making the attack complexity high. Successful exploitation results in heap memory corruption and a denial of service (DoS). The issue is resolved in versions 7.1.2-26 and 6.9.13-51.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26, < 6.9.13-51

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: NVD publication date

References

Related threats