Back

MEDIUM

ImageMagick before 7.1.2-26 Memory Leak in ICON decoder

Published Jul 15, 2026

Description

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Red Hat mitigation

Do not process untrusted image files with ImageMagick. The ICON coder can be disabled in ImageMagick's policy.xml if not needed: `<policy domain="coder" rights="none" pattern="ICON"/>`. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 15, 2026
Updated Jul 15, 2026
Reserved Jul 10, 2026
CISA Vulnrichment
Updated Jul 15, 2026
NVD
Status Deferred
Modified Jul 15, 2026
Red Hat
Severity Low
Public date Jul 15, 2026
ENISA EUVD
Assigner VulnCheck
Published Jul 15, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-44619