CVE-2026-28693: ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write
An integer overflow in DIB coder can result in out of bounds read or write
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Magick.NET-Q8-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q8-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x86to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64to a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
nuget/Magick.NET-Q16-AnyCPUto a version that resolves this vulnerability.Fixed in 14.10.4 - Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u14Fixed in 8:6.9.11.60+dfsg-1.6+deb12u9Fixed in 8:6.9.11.60+dfsg-1.6+deb12u11Fixed in 8:7.1.1.43+dfsg1-1+deb13u8Fixed in 8:7.1.1.43+dfsg1-1+deb13u10Fixed in 8:7.1.2.25+dfsg1-2 - Upgrade
Upgrade
ImageMagick DIB coderto a version that resolves this vulnerability.Fixed in 7.1.2-16 - Upgrade
Upgrade
ImageMagick DIB coderto a version that resolves this vulnerability.Fixed in 6.9.13-41
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28693?
CVE-2026-28693 has been classified as a high severity vulnerability due to the potential for out of bounds read or write.
How do I fix CVE-2026-28693?
To fix CVE-2026-28693, upgrade to ImageMagick version 7.1.2-16 or higher, or version 6.9.13-41 or higher.
What causes CVE-2026-28693?
CVE-2026-28693 is caused by an integer overflow in the DIB coder within ImageMagick.
What versions of ImageMagick are affected by CVE-2026-28693?
CVE-2026-28693 affects ImageMagick versions prior to 7.1.2-16 and 6.9.13-41.
What kind of attacks can CVE-2026-28693 facilitate?
CVE-2026-28693 can potentially facilitate remote code execution or lead to crashes due to out of bounds memory access.