ImageMagick before 7.1.2-26 Memory Leak in ICON decoder
Published Jul 15, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.35%
Description
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.
Affected products
-
- Version 0StatusaffectedConstraints<6.9.13-51
- Version 0StatusaffectedConstraints<7.1.2-26
- Version 6.9.13-51StatusunaffectedConstraints-
- Version 7.1.2-26StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ImageMagick | ImageMagick | unaffected |
|
No data.
No data.
Red Hat Enterprise Linux 6
ImageMagick
Fix deferred
Red Hat Enterprise Linux 7
ImageMagick
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ImageMagick | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | ImageMagick | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
Do not process untrusted image files with ImageMagick. The ICON coder can be disabled in ImageMagick's policy.xml if not needed: `<policy domain="coder" rights="none" pattern="ICON"/>`. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-61871 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2500909 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44619 Advisory
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-61871
- https://www.cve.org/CVERecord?id=CVE-2026-61871
- https://www.vulncheck.com/advisories/imagemagick-before-26-memory-leak-in-icon-decoder third-party-advisory
Change history (0)
No recorded changes yet.