| Name | CVE-2026-105401 |
| Description | ImageMagick before 7.1.2-31 contains a heap buffer overflow vulnerability in the distributed pixel cache server that allows connecting clients to overwrite heap memory by sending crafted data. Attackers can connect to the distributed pixel cache server and transmit malicious data to trigger a heap buffer over-write that crashes the server, causing denial of service. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| imagemagick (PTS) | bookworm | 8:6.9.11.60+dfsg-1.6+deb12u11 | vulnerable |
| bookworm (security) | 8:6.9.11.60+dfsg-1.6+deb12u13 | vulnerable |
| trixie | 8:7.1.1.43+dfsg1-1+deb13u12 | vulnerable |
| trixie (security) | 8:7.1.1.43+dfsg1-1+deb13u11 | vulnerable |
| forky, sid | 8:7.1.2.31+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| imagemagick | source | (unstable) | 8:7.1.2.31+dfsg1-1 | | | |
Notes
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92
Duplicate of CVE-2026-106574, report to VulnCheck CNA for rejection