CVE-2026-56373: ImageMagick - Use-After-Free Write in PDB Decoder
Published Jul 10, 2026
·Updated
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.
Affected Software
3 affected components
ImageMagick ImageMagick<7.1.2-15
ImageMagick ImageMagick<6.9.13-40
ImageMagick ImageMagick>=7.0.0-0<7.1.2-15
Event History
Jul 10, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56373?
CVE-2026-56373 has a medium severity rating of 6.3.
2
How do I fix CVE-2026-56373?
To fix CVE-2026-56373, update ImageMagick to version 7.1.2-15 or later.
3
What causes the vulnerability in CVE-2026-56373?
CVE-2026-56373 is caused by a use-after-free condition in the PDB decoder that utilizes a stale pointer.
4
What types of attacks can be performed using CVE-2026-56373?
Attackers can exploit CVE-2026-56373 by processing malicious PDB files to cause application crashes or write to freed memory.
5
Which software is affected by CVE-2026-56373?
CVE-2026-56373 affects versions of ImageMagick prior to 7.1.2-15.