Home

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or potentially lead to an out of bounds heap write. Version 7.1.2-15 contains a patch.

PUBLISHED Reserved 2026-02-05 | Published 2026-02-24 | Updated 2026-02-24 | Assigner GitHub_M




HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Problem types

CWE-122: Heap-based Buffer Overflow

CWE-190: Integer Overflow or Wraparound

Product status

< 7.1.2-15
affected

References

github.com/...Magick/security/advisories/GHSA-vhqj-f5cj-9x8h

cve.org (CVE-2026-25794)

nvd.nist.gov (CVE-2026-25794)

Download JSON