CVE-2026-28691: ImageMagick has an uninitialized pointer dereference in JBIG decoder
An uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Magick.NET-Q8-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u14Fixed in 8:6.9.11.60+dfsg-1.6+deb12u9Fixed in 8:6.9.11.60+dfsg-1.6+deb12u11Fixed in 8:7.1.1.43+dfsg1-1+deb13u8Fixed in 8:7.1.1.43+dfsg1-1+deb13u10Fixed in 8:7.1.2.25+dfsg1-2 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-16 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-41
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28691?
CVE-2026-28691 is considered a high severity vulnerability due to the potential for exploitation leading to application crashes.
How do I fix CVE-2026-28691?
To fix CVE-2026-28691, update ImageMagick to versions 7.1.2-16 or 6.9.13-41 or later.
What types of systems are affected by CVE-2026-28691?
CVE-2026-28691 affects systems running older versions of ImageMagick prior to the specified patched versions.
What does CVE-2026-28691 exploit specifically?
CVE-2026-28691 exploits an uninitialized pointer dereference in the JBIG decoder of ImageMagick.
Is CVE-2026-28691 easy to exploit?
Yes, CVE-2026-28691 can be relatively easy to exploit given the right conditions and lacks adequate input validation.