Memory leak in ImageMagick - #VU135678

 

Memory leak in ImageMagick - #VU135678

Published: June 29, 2026


Vulnerability identifier: #VU135678
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the color transformation to log colorspace operation when transforming an image to the log colorspace and the operation fails. A remote attacker can trigger a failed image transformation to cause a denial of service.


Affected software

ImageMagick

Remediation

Install security update from vendor's website.

ImageMagick - addressed in versions 6.9.13-51, 7.1.2-26

External References

Related Security Bulletins