CVE-2026-106575: ImageMagick: Unclosed file pointer in magick script
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments running ImageMagick versions before 7.1.2-31 are affected if they process Magick scripts. Repeated processing of a crafted script can exhaust available file descriptors.
What does an attacker need to exploit it?
An attacker needs to cause the affected ImageMagick instance to process a crafted Magick script. The supplied severity vector indicates no privileges or user interaction are required and the attack can be performed over a network-accessible path.
What is the impact of successful exploitation?
The impact is availability loss: unclosed file pointers accumulate during repeated processing until available file descriptors are exhausted. The provided vector indicates no confidentiality or integrity impact.
What should be done if patching cannot happen immediately?
The provided data identifies upgrading to ImageMagick 7.1.2-31 as the fix. No alternative mitigation is specified.