CVE-2026-106571: ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a crash
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels API can trigger an integer calculation error and write beyond a heap buffer, crashing the server process. This issue is fixed in versions 6.9.13-56 and 7.1.2-31.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-56 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
ImageMagick versions before 6.9.13-56 and before 7.1.2-31 are affected when code makes a crafted local call to the GetVirtualPixels API. The documented impact is a crash of the server process.
What does an attacker need to exploit the flaw?
Exploitation requires a crafted local call to the GetVirtualPixels API. The provided data does not describe a remote attack path or user interaction requirement.
What should teams do to remediate the issue?
Upgrade ImageMagick 6 to 6.9.13-56 or later, or ImageMagick 7 to 7.1.2-31 or later.