CVE-2026-27799: ImageMagick has a heap Buffer Over-read in its DJVU image format handler

Published Feb 25, 2026
·
Updated

A heap Buffer Over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads.

Affected Software

21 affected componentsFixes available
ImageMagick ImageMagick<6.9.13-40
ImageMagick ImageMagick>=7.0.0-0<7.1.2-15
Dlemstra Magick.net<14.10.3
nuget/Magick.NET-Q8-x86<14.10.3
14.10.3
nuget/Magick.NET-Q8-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-AnyCPU<14.10.3
14.10.3
debian/imagemagick<=8:6.9.11.60+dfsg-1.3+deb11u4
8:6.9.11.60+dfsg-1.3+deb11u148:6.9.11.60+dfsg-1.6+deb12u98:6.9.11.60+dfsg-1.6+deb12u118:7.1.1.43+dfsg1-1+deb13u88:7.1.1.43+dfsg1-1+deb13u108:7.1.2.25+dfsg1-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nuget/Magick.NET-Q8-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  2. Upgrade

    Upgrade nuget/Magick.NET-Q8-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  3. Upgrade

    Upgrade nuget/Magick.NET-Q8-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  4. Upgrade

    Upgrade nuget/Magick.NET-Q8-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  5. Upgrade

    Upgrade nuget/Magick.NET-Q8-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  6. Upgrade

    Upgrade nuget/Magick.NET-Q8-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  7. Upgrade

    Upgrade nuget/Magick.NET-Q16-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  8. Upgrade

    Upgrade nuget/Magick.NET-Q16-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  9. Upgrade

    Upgrade nuget/Magick.NET-Q16-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  10. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  11. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  12. Upgrade

    Upgrade nuget/Magick.NET-Q16-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  13. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-x86 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  14. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  15. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  16. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-OpenMP-x64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  17. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-OpenMP-arm64 to a version that resolves this vulnerability.

    Fixed in 14.10.3
  18. Upgrade

    Upgrade nuget/Magick.NET-Q16-HDRI-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  19. Upgrade

    Upgrade nuget/Magick.NET-Q16-AnyCPU to a version that resolves this vulnerability.

    Fixed in 14.10.3
  20. Upgrade

    Upgrade debian/imagemagick to a version that resolves this vulnerability.

    Fixed in 8:6.9.11.60+dfsg-1.3+deb11u14Fixed in 8:6.9.11.60+dfsg-1.6+deb12u9Fixed in 8:6.9.11.60+dfsg-1.6+deb12u11Fixed in 8:7.1.1.43+dfsg1-1+deb13u8Fixed in 8:7.1.1.43+dfsg1-1+deb13u10Fixed in 8:7.1.2.25+dfsg1-2
  21. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.1.2-15Patch patch
  22. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.9.13-40Patch patch

Event History

Feb 25, 2026
Advisory Published
via GitHub·07:24 PM
Data Sourced
via GitHub·07:24 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·11:20 PM
Data Sourced
via MITRE·11:20 PM
DescriptionSeverityWeakness
Feb 26, 2026
Data Sourced
via NVD·12:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 26, 2026
Data Sourced
via Ubuntu·04:26 PM
RemedyDescriptionSeverityAffected Software
Jun 28, 2026
Data Sourced
via Debian·04:29 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-27799?

The severity of CVE-2026-27799 is significant due to potential out-of-bounds memory reads caused by a heap Buffer Over-read.

2

How do I fix CVE-2026-27799?

To fix CVE-2026-27799, update the affected software to version 14.10.3 or later.

3

Which software is affected by CVE-2026-27799?

CVE-2026-27799 affects various versions of Magick.NET packages including Magick.NET-Q8 and Magick.NET-Q16.

4

What type of vulnerability is CVE-2026-27799?

CVE-2026-27799 is a heap Buffer Over-read vulnerability due to integer truncation in stride calculations.

5

How can CVE-2026-27799 impact applications?

CVE-2026-27799 can lead to memory corruption and potential exploitation due to improper handling of image buffers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203