Junglewise Threat Intelligence

ImageMagick out-of-bounds read in morphology processing

Severity: low · CVSS 3.3 · Published 2026-04-14

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: ImageMagick, NuGet.

Executive brief

ImageMagick is a widely used software suite for editing and processing digital images. A flaw in how it handles certain image transformation operations could allow a specially crafted image to cause the program to crash. This primarily impacts the reliability of services that automatically process user-uploaded images, though it does not appear to expose sensitive data.

Technical details

An off-by-one error (CWE-193) exists in ImageMagick's morphology processing component. The vulnerability is caused by incorrect origin validation, leading to an out-of-bounds read (CWE-125) of a single pixel. An attacker can exploit this by providing a specially crafted image file that triggers the morphology operation, potentially resulting in a heap-buffer-overflow and application crash (denial of service). The attack requires local access and user interaction (opening the file). The issue is addressed in Magick.NET version 14.12.0.

Affected products

  • ImageMagick Magick.NET-Q16-AnyCPU < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-OpenMP-x64 < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-x64 < 14.12.0
  • ImageMagick Magick.NET-Q16-HDRI-x86 < 14.12.0
  • ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.12.0
  • ImageMagick Magick.NET-Q16-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q16-x64 < 14.12.0
  • ImageMagick Magick.NET-Q16-x86 < 14.12.0
  • ImageMagick Magick.NET-Q8-AnyCPU < 14.12.0
  • ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.12.0
  • ImageMagick Magick.NET-Q8-arm64 < 14.12.0
  • ImageMagick Magick.NET-Q8-x64 < 14.12.0
  • ImageMagick Magick.NET-Q8-x86 < 14.12.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-14: advisory
  • 2026-04-14: patched: First patched version 14.12.0 released.

References

Related threats