5.9

CVE-2026-106578

ImageMagick: Invalid Memory Free in MVG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt ImageMagick
Version < 6.9.13-56
Status affected
Version >= 7.0.0, < 7.1.2-31
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-590 Free of Memory not on the Heap

The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().

https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39
https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378
https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d