Executive brief
ImageMagick is a software suite used to create, edit, and convert images. A memory leak has been identified when the software fails to transform an image into a specific color format. While the impact is low, repeated failures could gradually consume system memory, potentially slowing down or destabilizing applications that process many images.
Technical details
A memory leak (CWE-401) exists in ImageMagick during color transformation operations. Specifically, when a transformation to the log colorspace fails, the application fails to release previously allocated memory. This is a local vulnerability with high attack complexity, as it requires triggering a specific failure state during image processing. An attacker could potentially cause a minor denial-of-service condition through resource exhaustion if they can repeatedly trigger these failed transformations. The issue is addressed in Magick.NET version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-x86 < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-x86 < 14.15.0
Timeline
- 2026-06-26: disclosed
- 2026-07-24: advisory
- 2026-07-24: patched: Magick.NET 14.15.0 released