PT-2026-3526 · Unknown · Imagemagick
Lemstra
·
Published
2026-01-04
·
Updated
2026-03-09
·
CVE-2026-22770
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-13
Description
ImageMagick is software used for editing and manipulating digital images. A flaw exists in the
BilateralBlurImage method where double buffers allocated inside AcquireBilateralTLS are not fully initialized. This can lead to the release of an invalid pointer within the DestroyBilateralTLS function when memory allocation fails.Recommendations
Update ImageMagick to version 7.1.2-13 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick