Low severity1.9NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-56364
CVE-2026-56364
Description
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
Affected products
6<7.1.2-13+ 2 more
- (no CPE)range: <7.1.2-13
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <7.1.2-13
- (no CPE)range: <7.1.2-13
- osv-coords3 versionspkg:apk/chainguard/imagemagick-6pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweed
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 7.1.2.0-160000.11.1
- (no CPE)range: < 7.1.2.27-1.1
Patches
Vulnerability mechanics
References
3- github.com/ImageMagick/ImageMagick/commit/a52c1b402be08ef8ae193f28ac5b2e120f2fa26fnvdPatch
- www.vulncheck.com/advisories/imagemagick-memory-leak-in-loadopencldevicebenchmark-via-malformed-xmlnvdPatchThird Party Advisory
- github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp59-x883-77qvnvdExploitVendor Advisory
News mentions
2- ImageMagick: Fourteen Vulnerabilities Disclosed in Batch, Affecting Multiple VersionsVypr Intelligence · Jul 2, 2026
- ImageMagick: Six Vulnerabilities Disclosed, Including File Write and Info Disclosure FlawsVypr Intelligence · Jul 1, 2026