Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing image files. A flaw in how the software handles TIFF images could allow an attacker to cause the application to consume excessive system memory. If successfully exploited, this could lead to a denial-of-service condition where the application or the system it is running on becomes unresponsive.
Technical details
A memory leak vulnerability (CWE-401) exists in the TIFF encoder of ImageMagick versions prior to 7.1.2-26. The issue occurs when a memory allocation failure is encountered during the encoding process, resulting in the software failing to release previously allocated memory. An attacker can exploit this by providing specially crafted TIFF images or triggering specific environmental conditions that cause allocation failures. While the attack complexity is high and requires local access, repeated exploitation can lead to memory exhaustion and a denial-of-service (DoS) state. The vulnerability is addressed in version 7.1.2-26.
Affected products
- ImageMagick ImageMagick < 7.1.2-26
Timeline
- 2026-06-26: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date
- 2026-07-15: patched: Fix confirmed in version 7.1.2-26