CVE-2026-61863: ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder
ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.6+deb12u13Fixed in 8:7.1.1.43+dfsg1-1+deb13u12Fixed in 8:7.1.2.29+dfsg2-1Fixed in 8:7.1.2.31+dfsg1-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-51
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61863?
The severity of CVE-2026-61863 is classified as low, with a rating of 2.1.
What does CVE-2026-61863 affect?
CVE-2026-61863 affects ImageMagick versions before 7.1.2-26 and 6.x versions before 6.9.13-51.
What is the vulnerability in CVE-2026-61863?
CVE-2026-61863 is a memory leak vulnerability occurring in the TIFF encoder when a temporary file cannot be created.
How do I mitigate CVE-2026-61863?
To mitigate CVE-2026-61863, update ImageMagick to version 7.1.2-26 or later, or to version 6.9.13-51 or later.
Can CVE-2026-61863 lead to data loss?
CVE-2026-61863 does not directly cause data loss but could lead to increased memory usage due to the memory leak.