Out-of-bounds write in ImageMagick - CVE-2026-48724
Published: May 31, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the Floyd-Steinberg depth dithering functionality when processing a crafted image with a mask. A remote attacker can trick the victim into opening a crafted image to cause a denial of service.
User interaction is required to open or process a crafted image.