CVE-2026-56362: ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization
ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56362?
The severity of CVE-2026-56362 is low, with a score of 3.3.
How do I fix CVE-2026-56362?
To fix CVE-2026-56362, update ImageMagick to version 7.1.2-15 or later.
What type of vulnerability is CVE-2026-56362?
CVE-2026-56362 is a heap-buffer-overflow read vulnerability.
What impact can CVE-2026-56362 have on my system?
CVE-2026-56362 can lead to memory and disk allocation failures, potentially affecting the stability of the application.
Which software is affected by CVE-2026-56362?
CVE-2026-56362 affects ImageMagick versions prior to 7.1.2-15.