CVE-2026-106567: ImageMagick: Infinite Loop in PSD decoder on 32-bit builds
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-32 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-57
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects 32-bit builds of ImageMagick running versions earlier than 7.1.2-32 or 6.9.13-57. The provided information does not indicate that 64-bit builds are affected.
What does an attacker need to exploit this issue?
An attacker needs to provide a crafted PSD file for ImageMagick to decode. No authentication or user interaction is required according to the supplied vector, but exploitation has high attack complexity.
What is the impact of successful exploitation?
The crafted file can trigger an integer-conversion error in the PSD decoder, causing an infinite loop and denial of service. The supplied vector indicates no confidentiality or integrity impact.
What should be done if systems are vulnerable?
Upgrade ImageMagick to 7.1.2-32 or later, or to 6.9.13-57 or later. If an upgrade cannot be applied immediately, the provided data does not specify a mitigation.