Back

CRITICAL

ImageMagick's MSL: Stack overflow in ProcessMSLScript

Published Feb 24, 2026

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular references between two MSLs, leading to a stack overflow. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

Affected products

Remediation

Red Hat statement

This MODERATE impact vulnerability in ImageMagick arises from a stack overflow when processing maliciously crafted MSL files containing circular references. Red Hat Enterprise Linux and Community Projects are affected where ImageMagick is used to process untrusted image or script files.

Red Hat mitigation

To mitigate this issue, avoid processing untrusted or maliciously crafted MSL (Magick Scripting Language) files with ImageMagick. Implement strict input validation and sanitization for any ImageMagick operations that handle external or user-supplied content.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 24, 2026
Updated Jun 23, 2026
Reserved Feb 9, 2026
CISA Vulnrichment
Updated Feb 26, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 24, 2026
ENISA EUVD
Assigner GitHub_M
Published Feb 24, 2026
Updated Jun 23, 2026
Exploited since n/a
EUVD-2026-7427 GHSA-8MPR-6XR2-CHHC