Low severity3.3OSV Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-56362
CVE-2026-56362
Description
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.
Affected products
57.1.2-14, 7.1.2-13, 7.1.2-12, …+ 2 more
- (no CPE)range: 7.1.2-14, 7.1.2-13, 7.1.2-12, …
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-40
- (no CPE)range: <7.1.2-15
- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 7.1.2.0-160000.12.1+ 1 more
- (no CPE)range: < 7.1.2.0-160000.12.1
- (no CPE)range: < 7.1.2.27-1.1
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026