CVE-2026-107209
MEDIUM
5,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
415
Double Free
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Modify Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Memory-Unsafe, C, C++
416
Use After Free
StableCommon Consequences
Security Scopes Affected:
Integrity
Availability
Confidentiality
Potential Impacts:
Modify Memory
Dos: Crash, Exit, Or Restart
Read Memory
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
Memory-Unsafe, C, C++
https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044…
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55
https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063d…
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3…