Executive brief
ImageMagick, a widely used software suite for displaying and editing images, is affected by a memory management flaw. If the software fails to initialize a specific font-rendering component (FreeType), it may continue to process data using memory that has already been released. In practice, this could allow an attacker to crash the application or service, leading to a disruption of operations.
Technical details
A use-after-free (UAF) vulnerability exists in ImageMagick's handling of FreeType initialization. When initialization fails, the affected method fails to exit properly and continues to access memory that has already been deallocated. This flaw is categorized under CWE-416. An attacker can trigger this condition during image processing, typically resulting in a denial of service (DoS) through application crashes. The vulnerability is reachable over the network but requires high attack complexity, as specific conditions must be met during the initialization phase. The issue is resolved in versions 7.1.2-26 and 6.9.13-51.
Affected products
- ImageMagick ImageMagick < 7.1.2-26
- ImageMagick ImageMagick < 6.9.13-51
Timeline
- 2026-06-26: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date