CVE-2026-93590

NameCVE-2026-93590
DescriptionImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)bookworm8:6.9.11.60+dfsg-1.6+deb12u11vulnerable
bookworm (security)8:6.9.11.60+dfsg-1.6+deb12u13vulnerable
trixie8:7.1.1.43+dfsg1-1+deb13u12vulnerable
trixie (security)8:7.1.1.43+dfsg1-1+deb13u11vulnerable
forky, sid8:7.1.2.31+dfsg1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)8:7.1.2.31+dfsg1-1

Notes

[trixie] - imagemagick <no-dsa> (Minor issue)
[bookworm] - imagemagick <postponed> (Minor issue)
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
Fixed by: https://github.com/ImageMagick/ImageMagick/commit/59046410c17e9421f0ad7b4bec478a892cf30c12 (7.1.2-31)

Search for package or bug name: Reporting problems