Back

MEDIUM

ImageMagick: Heap Buffer Over-Read in distributed pixel cache server

Published Jun 10, 2026

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

Affected products

Remediation

Red Hat statement

Moderate: This flaw in ImageMagick could lead to information disclosure and denial of service. Exploitation requires an attacker to have high privileges and local access to the system, specifically targeting the `magick -distribute-cache` service. This limits the overall risk in typical Red Hat Enterprise Linux deployments.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 10, 2026
Updated Jun 11, 2026
Reserved May 18, 2026
CISA Vulnrichment
Updated Jun 11, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date Jun 10, 2026
GHSA-6GXQ-F64P-5W6F