CVE-2026-23952: ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load
Summary
NULL pointer dereference in MSL (Magick Scripting Language) parser when processing <comment> tag before any image is loaded.
Version
- ImageMagick 7.x (tested on current main branch) - Commit: HEAD
Steps to Reproduce
Method 1: Using ImageMagick directly
bash magick MSL:poc.msl out.png
Method 2: Using OSS-Fuzz reproduce
bash python3 infra/helper.py buildfuzzers imagemagick python3 infra/helper.py reproduce imagemagick mslfuzzer poc.msl
Or run the fuzzer directly: bash ./mslfuzzer poc.msl
Expected Behavior
ImageMagick should handle the malformed MSL gracefully and return an error message.
Actual Behavior
convert: MagickCore/property.c:297: MagickBooleanType DeleteImageProperty(Image , const char ): Assertion image != (Image ) NULL' failed. Aborted
Root Cause Analysis
In coders/msl.c:7091, MSLEndElement() calls DeleteImageProperty() on mslinfo->image[n] when handling the </comment> end tag without checking if the image is NULL:
c if (LocaleCompare((const char ) tag,"comment") == 0 ) { (void) DeleteImageProperty(mslinfo->image[n],"comment"); // No NULL check ... }
When <comment> appears before any <read> operation, mslinfo->image[n] is NULL, causing the assertion failure in DeleteImageProperty() at property.c:297.
Impact
- DoS: Crash via assertion failure (debug builds) or NULL pointer dereference (release builds) - Affected: Any application using ImageMagick to process user-supplied MSL files
Fuzzer
This issue was discovered using a custom MSL fuzzer:
cpp #include <cstdint> #include <Magick++/Blob.h> #include <Magick++/Image.h> #include "utils.cc"
extern "C" int LLVMFuzzerTestOneInput(const uint8t Data, sizet Size) { if (IsInvalidSize(Size)) return(0); try { const Magick::Blob blob(Data, Size); Magick::Image image; image.magick("MSL"); image.fileName("MSL:"); image.read(blob); } catch (Magick::Exception) { } return(0); }
This issue was found by Team FuzzingBrain @ Texas A&M University
Other sources
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23952?
CVE-2026-23952 has been classified as a high severity vulnerability due to the potential for a NULL pointer dereference.
How do I fix CVE-2026-23952?
To mitigate CVE-2026-23952, upgrade to Magick.NET version 14.10.2 or later.
Which versions of ImageMagick are affected by CVE-2026-23952?
CVE-2026-23952 affects all versions of ImageMagick 7.x up to version 14.10.2.
What type of vulnerability is CVE-2026-23952?
CVE-2026-23952 is a NULL pointer dereference vulnerability found in the MSL parser.
How can I determine if I'm using an affected version related to CVE-2026-23952?
Check your ImageMagick or Magick.NET package version to see if it is below version 14.10.2 to determine if you are affected by CVE-2026-23952.