CVE-2026-107209: ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-30 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-55
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use ImageMagick versions earlier than 7.1.2-30 or 6.9.13-55 and were built without Cairo support. Builds with Cairo support are not described as affected.
What is required to trigger the issue?
An attacker needs to get a crafted RSVG image processed by the vulnerable decoder. The image must reach a resource limit, which can cause image state to be freed twice and then accessed after free.
What is the practical impact?
Successful triggering can crash the ImageMagick process, resulting in a denial of service. The provided data does not describe confidentiality or integrity impact.
What versions fix the vulnerability?
Upgrade ImageMagick to version 7.1.2-30 or later, or 6.9.13-55 or later.