Memory allocation with excessive without limits in the internal SVG decoder
Published Feb 24, 2026
7.5
HIGHCVSS 3.1
EPSS 0.66%
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Affected products
-
- Version < 6.9.13-40StatusaffectedConstraints-
- Version >= 7.0.0, < 7.1.2-15StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick | ImageMagick | n/a |
|
- < 6.9.13-40
- ≥ 7.0.0-0 · < 7.1.2-15
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
ImageMagick-0:6.9.10.68-13.el7_9
Fixed · RHSA-2026:5573
Red Hat Enterprise Linux 6
ImageMagick
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | ImageMagick-0:6.9.10.68-13.el7_9 | Fixed | RHSA-2026:5573 |
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is classified as High severity by Red Hat Product Security. A remote attacker can craft an SVG image that, when processed by ImageMagick, induces extremely large memory allocation requests, leading to process failure or termination. The attack complexity is low and does not require any privileges or user interaction. While confidentiality and integrity are not directly impacted, the availability of services that parse or manipulate untrusted SVG images could be significantly disrupted over network, justifying a High severity rating. ``` It is important to note that ImageMagick has been removed from Red Hat Enterprise Linux 8 and later releases. Therefore, current supported RHEL 8 and newer systems are not affected by this issue unless ImageMagick is installed from third-party or custom repositories. For additional information, refer to https://access.redhat.com/solutions/4437561. ```
Red Hat mitigation
To mitigate this vulnerability, avoid processing untrusted or unverified SVG image files with ImageMagick. When ImageMagick must process SVG files from untrusted sources, consider running the application in a sandboxed environment to limit potential resource exhaustion impacts.
References (11)
- https://access.redhat.com/errata/RHSA-2026:5573
- https://access.redhat.com/security/cve/CVE-2026-25985 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2442127 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7423 Advisory
- https://github.com/ImageMagick/ImageMagick/commit/1a51eb9af00c36724660e294520878fd1f13e312
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84 x_refsource_CONFIRMThird Party Advisory
- https://github.com/advisories/GHSA-v7g2-m8c5-mf84 Advisory
- https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3
- https://nvd.nist.gov/vuln/detail/CVE-2026-25985
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json
- https://www.cve.org/CVERecord?id=CVE-2026-25985
Change history (0)
No recorded changes yet.