VYPR
Medium severity5.5GHSA Advisory· Published May 18, 2026· Updated May 18, 2026

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

CVE-2026-46521

Description

When using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds write in ImageMagick's MIFF encoder when using LZMA compression can lead to heap memory corruption.

Vulnerability

When LZMA compression is selected in the MIFF encoder of ImageMagick, an out-of-bounds write occurs due to a missing bounds check. This affects ImageMagick and downstream wrappers such as Magick.NET versions prior to 14.13.1 [2]. The bug resides in the encoder's handling of compressed data streams during MIFF file creation [3].

Exploitation

An attacker must supply a specially crafted image that triggers the LZMA compression path in the MIFF encoder. No authentication is required, but user interaction (e.g., opening the malicious file) is needed. The attack can be performed remotely via crafted files served through applications that use ImageMagick to process images [3].

Impact

Successful exploitation results in a heap-buffer over-write, which can lead to denial of service, data corruption, or potential code execution. The vulnerability has moderate severity, with CVSS metrics indicating high availability impact [3]. An attacker may disrupt the affected service or compromise the integrity of memory contents.

Mitigation

Upgrade ImageMagick to a patched version (release details expected from the maintainer). For Magick.NET, versions 14.13.1 and later contain the fix [2]. If immediate patching is not possible, avoid using LZMA compression in the MIFF encoder by switching to a different compression method or format. No workaround is disclosed in the available references.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.