CVE-2026-105398: ImageMagick before 7.1.2-31 Heap Buffer Overflow via GetVirtualPixels API
Published Oct 8, 2026
·Updated
Rejected reason: This CVE ID has been rejected as a duplicate.
Affected Software
1 affected component
ImageMagick ImageMagick<7.1.2-31
Event History
Oct 8, 2026
CVE Published
via MITRE·02:10 PM
Rejected
via MITRE·02:10 PM
Data Sourced
via NVD·03:17 PM
Description
Oct 9, 2026
Rejected
via MITRE·01:03 PM
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The listed vector is local with high attack complexity, and no privileges or user interaction are required. Exploitation requires making a crafted call to the GetVirtualPixels API with crafted input.
2
What is the practical impact of successful exploitation?
The described impact is a heap out-of-bounds write that can overwrite heap memory and crash the server, resulting in denial of service. The provided vector does not indicate confidentiality or integrity impact.
3
Which ImageMagick versions need remediation?
ImageMagick versions before 7.1.2-31 are affected. Upgrade to 7.1.2-31 or a later version.