CVE-2026-56378: ImageMagick - Heap Out-of-Bounds Read in PCD Decoder
ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.6+deb12u13Fixed in 8:7.1.1.43+dfsg1-1+deb13u11Fixed in 8:7.1.2.29+dfsg2-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-15 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-40
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56378?
The severity of CVE-2026-56378 is classified as low with a score of 3.7.
What are the implications of CVE-2026-56378?
CVE-2026-56378 may lead to denial of service and potential disclosure of adjacent heap memory during image decoding.
How do I fix CVE-2026-56378?
To fix CVE-2026-56378, upgrade to ImageMagick version 7.1.2-15 or 6.9.13-40 and later.
Who is affected by CVE-2026-56378?
CVE-2026-56378 affects users of ImageMagick versions prior to 7.1.2-15 or those using 6.x versions prior to 6.9.13-40.
What types of file can trigger CVE-2026-56378?
A crafted PCD file can trigger the vulnerability CVE-2026-56378 during the image decoding process.