CVE-2026-106572: ImageMagick: Stack Overflown CALS decoder due to missing depth check.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-30 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-55
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using ImageMagick versions earlier than 7.1.2-30 or 6.9.13-55 are affected when they process CALS images. The issue can be triggered remotely without authentication or user interaction if an attacker can cause the deployment to decode a crafted CALS file.
What is the practical impact of successful exploitation?
A crafted CALS image can exhaust the decoder's call stack and terminate the ImageMagick process. The reported impact is denial of service; no confidentiality or integrity impact is specified.
What should be done if an immediate upgrade is not possible?
The provided information does not specify a workaround. Until upgrading to 7.1.2-30 or 6.9.13-55, avoid processing untrusted CALS images where possible.