PT-2026-21624 · Unknown+2 · Imagemagick+2

Ylwango613

·

Published

2026-02-06

·

Updated

2026-05-11

·

CVE-2026-25898

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-15 ImageMagick versions prior to 6.9.13-40
Description ImageMagick is software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder does not properly check the pixel index value returned by the GetPixelIndex() function before it is used. In builds that use High Dynamic Range Imaging (HDRI), the Quantum type is a floating-point type, which allows pixel index values to be negative. An attacker can create a specially crafted image with negative pixel index values to cause a buffer overflow read during image conversion, potentially leading to information disclosure or a process crash.
Recommendations Update to ImageMagick version 7.1.2-15 or later. Update to ImageMagick version 6.9.13-40 or later.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-06711
CVE-2026-25898
ECHO-0472-DF21-4262
GHSA-VPXV-R9PG-7GPR
OESA-2026-1452
OESA-2026-1453
OESA-2026-1454
OESA-2026-1455
OESA-2026-1456
OESA-2026-1457
OPENSUSE-SU-2026:10267-1
OPENSUSE-SU-2026:20337-1
SUSE-SU-2026:0851-1
SUSE-SU-2026:0852-1
SUSE-SU-2026:0853-1
USN-8069-1
USN-8263-1

Affected Products

Imagemagick
Linuxmint
Ubuntu