ImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output buffer
Published Mar 9, 2026
6.8
MEDIUMCVSS 3.1
EPSS 0.16%
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, A heap-buffer-overflow vulnerability exists in the PCL encode due to an undersized output buffer allocation. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Affected products
-
- Version < 6.9.13-41StatusaffectedConstraints-
- Version >= 7.0.0, < 7.1.2-16StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick | ImageMagick | n/a |
|
- < 6.9.13-41
- ≥ 7.0.0-0 · < 7.1.2-16
No data.
Red Hat Enterprise Linux 6
ImageMagick
Out of support scope
Red Hat Enterprise Linux 7
ImageMagick
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ImageMagick | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This MODERATE impact vulnerability in ImageMagick involves a heap-buffer-overflow within the PCL encoder. Processing a specially crafted image could trigger this flaw, potentially leading to denial of service or other impacts. This affects Red Hat Enterprise Linux 6 ELS and 7 ELS, as well as community projects like Fedora and EPEL, where ImageMagick is used for image processing.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-28686 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2445889 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-10375 Advisory
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-467j-76j7-5885 x_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-467j-76j7-5885 Advisory
- https://github.com/dlemstra/Magick.NET/releases/tag/14.10.4
- https://nvd.nist.gov/vuln/detail/CVE-2026-28686
- https://www.cve.org/CVERecord?id=CVE-2026-28686
Change history (0)
No recorded changes yet.