Junglewise Threat Intelligence

ImageMagick memory leak in hough lines operation

Severity: low · CVSS 2.9 · Published 2026-07-24

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Dlemstra Magick.NET, Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, Dlemstra, ImageMagick.

Executive brief

ImageMagick is a software suite used for creating, editing, and converting images. A vulnerability exists where certain image processing operations fail to properly release memory. If triggered repeatedly, this could lead to a gradual depletion of system resources, potentially slowing down or crashing applications that rely on the library.

Technical details

A memory leak (CWE-401) exists in ImageMagick's hough lines operation. The vulnerability is triggered when a specific operation within the hough lines logic fails, causing the product to fail to release allocated memory. An attacker with local access could potentially exploit this to cause a minor denial-of-service through resource exhaustion, though the attack complexity is high and the impact is limited to availability. The issue is fixed in ImageMagick versions 7.1.2-26 and 6.9.13-51, and Magick.NET version 14.15.0.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26, < 6.9.13-51
  • dlemstra Magick.NET < 14.15.0

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: patched: Initial patch release for ImageMagick
  • 2026-07-24: advisory

References

Related threats