CVE-2026-30929: ImageMagick has a stack buffer overflow in MagnifyImage
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, MagnifyImage uses a fixed-size stack buffer. When using a specific image it is possible to overflow this buffer and corrupt the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30929?
CVE-2026-30929 has a high severity due to the stack buffer overflow vulnerability that can lead to potential code execution.
How do I fix CVE-2026-30929?
To fix CVE-2026-30929, update ImageMagick to versions 7.1.2-16 or 6.9.13-41 or later.
What type of vulnerability is CVE-2026-30929?
CVE-2026-30929 is classified as a stack buffer overflow vulnerability.
Which versions of ImageMagick are affected by CVE-2026-30929?
CVE-2026-30929 affects versions of ImageMagick prior to 7.1.2-16 and 6.9.13-41.
What is MagnifyImage in the context of CVE-2026-30929?
MagnifyImage is a function in ImageMagick that is vulnerable to stack buffer overflow in specific scenarios involving certain image files.