CVE-2026-25898: Imagemagick Has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer

Published Feb 24, 2026
·
Updated

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by GetPixelIndex() before using it as an array subscript. In HDRI builds, Quantum is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

Other sources

The UIL and XPM image encoder do not validate the pixel index value returned by GetPixelIndex() before using it as an array subscript. In HDRI builds, Quantum is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash.

READ of size 1 at 0x55a8823a776e thread T0 #0 0x55a880d01e85 in WriteUILImage coders/uil.c:355

READ of size 1 at 0x55fa1c04c66e thread T0 #0 0x55fa1a9ee415 in WriteXPMImage coders/xpm.c:1135

GitHub

Affected Software

20 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-15, <6.9.13-40
nuget/Magick.NET-Q8-x86<14.10.3
14.10.3
nuget/Magick.NET-Q8-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-AnyCPU<14.10.3
14.10.3
ImageMagick ImageMagick<6.9.13-40
ImageMagick ImageMagick>=7.0.0-0<7.1.2-15
debian/imagemagick<=8:6.9.11.60+dfsg-1.3+deb11u4, <=8:6.9.11.60+dfsg-1.6+deb12u5, <=8:7.1.1.43+dfsg1-1+deb13u5
8:6.9.11.60+dfsg-1.3+deb11u128:6.9.11.60+dfsg-1.6+deb12u98:7.1.1.43+dfsg1-1+deb13u88:7.1.2.18+dfsg1-18:7.1.2.21+dfsg1-1

Event History

Feb 24, 2026
CVE Published
via MITRE·01:18 AM
Data Sourced
via MITRE·01:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:39 PM
Data Sourced
via GitHub·03:39 PM
DescriptionSeverityWeaknessAffected Software
May 13, 2026
Data Sourced
via Debian·04:06 AM
DescriptionAffected Software
Data Sourced
via Launchpad·04:06 AM
Description
May 14, 2026
Data Sourced
via Ubuntu·04:06 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-25898?

CVE-2026-25898 has a high severity due to its potential for a global buffer overflow leading to application crashes or arbitrary code execution.

2

How do I fix CVE-2026-25898?

To fix CVE-2026-25898, upgrade ImageMagick to version 7.1.2-15 or 6.9.13-40 and later.

3

What software is affected by CVE-2026-25898?

CVE-2026-25898 affects ImageMagick versions prior to 7.1.2-15 and 6.9.13-40.

4

Can CVE-2026-25898 lead to data leakage?

Yes, CVE-2026-25898 can potentially lead to data leakage due to the buffer overflow vulnerabilities.

5

What types of attacks can exploit CVE-2026-25898?

Attackers can exploit CVE-2026-25898 through crafted image files that trigger the buffer overflow in UIL and XPM encoders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203