CVE-2025-55005

NameCVE-2025-55005
DescriptionImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1111102

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)bullseye8:6.9.11.60+dfsg-1.3+deb11u4fixed
bullseye (security)8:6.9.11.60+dfsg-1.3+deb11u6fixed
bookworm8:6.9.11.60+dfsg-1.6+deb12u3fixed
bookworm (security)8:6.9.11.60+dfsg-1.6+deb12u4fixed
trixie8:7.1.1.43+dfsg1-1+deb13u1vulnerable
trixie (security)8:7.1.1.43+dfsg1-1+deb13u2fixed
forky, sid8:7.1.2.3+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksourcebullseye(not affected)
imagemagicksourcebookworm(not affected)
imagemagicksourcetrixie8:7.1.1.43+dfsg1-1+deb13u2
imagemagicksource(unstable)8:7.1.2.1+dfsg1-11111102

Notes

[bookworm] - imagemagick <not-affected> (Vulnerable code not present, specific to IM7)
[bullseye] - imagemagick <not-affected> (Vulnerable code not present, specific to IM7)
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v393-38qx-v8fp
https://github.com/ImageMagick/ImageMagick/commit/b68bb6d3cfe472d5bd9329b4172e2e4f63d90a57 (7.1.2-1)

Search for package or bug name: Reporting problems