PT-2026-25980 · Unknown+2 · Imagemagick+2

Fumfel

·

Published

2026-03-17

·

Updated

2026-04-22

·

CVE-2026-32636

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-17 ImageMagick versions prior to 6.9.13-42
Description ImageMagick is software used for editing and manipulating digital images. A bug exists in the NewXMLTree method that could cause a crash due to an out-of-bounds write of a single zero byte.
Recommendations Update ImageMagick to version 7.1.2-17 or later. Update ImageMagick to version 6.9.13-42 or later.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-32636
ECHO-971D-E2B5-F43C
GHSA-GC62-2V5P-QPMP
OESA-2026-1717
OESA-2026-1718
OESA-2026-1719
OESA-2026-1720
OESA-2026-1721
OESA-2026-1722
OPENSUSE-SU-2026:10446-1
OPENSUSE-SU-2026:20606-1
RHSA-2026:17618
SUSE-SU-2026:1202-1
SUSE-SU-2026:1203-1
SUSE-SU-2026:1497-1
SUSE-SU-2026:21380-1
USN-8127-1

Affected Products

Imagemagick
Linuxmint
Ubuntu