CVE-2026-106578: ImageMagick: Invalid Memory Free in MVG decoder
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-56
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running ImageMagick versions earlier than 7.1.2-31 or 6.9.13-56 are affected if they process attacker-crafted images through the MVG decoder.
What does an attacker need to exploit it?
An attacker needs to provide a crafted image that is processed by the MVG decoder. The provided vector indicates network reachability, no required privileges, and no user interaction, but exploitation has high attack complexity.
What is the impact of successful exploitation?
The crafted image can trigger an invalid memory free and crash the ImageMagick process, resulting in denial of service. The provided severity vector indicates no confidentiality or integrity impact.
What should be done if patching cannot happen immediately?
The available data does not provide a specific workaround. Prioritize preventing processing of untrusted images through the MVG decoder until ImageMagick can be updated.
How can I remediate the issue?
Update ImageMagick to version 7.1.2-31 or later, or version 6.9.13-56 or later for the 6.x branch.