CVE-2026-61861: ImageMagick before 7.1.2-26 Use-After-Free in FormatMagickCaption
ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61861?
The severity of CVE-2026-61861 is rated low with a score of 3.7.
What type of vulnerability is CVE-2026-61861?
CVE-2026-61861 is a use-after-free vulnerability that occurs in the FormatMagickCaption method.
What software is affected by CVE-2026-61861?
CVE-2026-61861 affects versions of ImageMagick prior to 7.1.2-26.
How do I fix CVE-2026-61861?
To mitigate CVE-2026-61861, update ImageMagick to version 7.1.2-26 or later.
What are the potential impacts of CVE-2026-61861?
CVE-2026-61861 can lead to denial of service or possibly allow code execution due to dangling pointers.