CVE-2026-56364: ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56364?
The severity of CVE-2026-56364 is classified as low with a score of 1.8.
How do I fix CVE-2026-56364?
To fix CVE-2026-56364, apply the available patch for ImageMagick.
What causes the memory leak in CVE-2026-56364?
The memory leak in CVE-2026-56364 is caused by parsing malformed OpenCL device profile XML files that contain unclosed device elements.
Who is affected by CVE-2026-56364?
Users of ImageMagick versions prior to 7.1.2-13 that allow attackers with write access to the OpenCL cache directory are affected by CVE-2026-56364.
What is the impact of CVE-2026-56364?
The impact of CVE-2026-56364 is that an attacker could exhaust memory on the system leading to a denial of service.