PT-2026-24127 · Unknown · Imagemagick

Ylwango613

·

Published

2026-01-01

·

Updated

2026-04-20

·

CVE-2026-28688

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-16 ImageMagick versions prior to 6.9.13-41
Description ImageMagick is software used for editing and manipulating digital images. A heap-use-after-free issue exists in the MSL encoder, where an image is destroyed twice. The MSL coder does not support writing MSL, and the write capability has been removed.
Recommendations Update ImageMagick to version 7.1.2-16 or later. Update ImageMagick to version 6.9.13-41 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-28688
ECHO-7719-678E-B834
GHSA-XXW5-M53X-J38C
OESA-2026-1692
OESA-2026-1693
OESA-2026-1694
OESA-2026-1695
OESA-2026-1696
OESA-2026-1697
OPENSUSE-SU-2026:10386-1
OPENSUSE-SU-2026:20405-1
SUSE-SU-2026:1201-1
SUSE-SU-2026:1202-1
SUSE-SU-2026:1203-1
SUSE-SU-2026:1497-1
SUSE-SU-2026:20917-1

Affected Products

Imagemagick