CVE-2026-61866: ImageMagick before 7.1.2-26 Memory Leak in JNG encoder
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.6+deb12u13Fixed in 8:7.1.1.43+dfsg1-1+deb13u12Fixed in 8:7.1.2.31+dfsg1-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61866?
CVE-2026-61866 has a low severity rating of 2.1.
How do I fix CVE-2026-61866?
To fix CVE-2026-61866, upgrade to ImageMagick version 7.1.2-26 or later.
What causes CVE-2026-61866?
CVE-2026-61866 is caused by a memory leak in the JNG encoder when it fails to open a malformed JNG file.
What are the potential impacts of CVE-2026-61866?
The potential impact of CVE-2026-61866 is resource exhaustion due to memory leaks.
Is CVE-2026-61866 exploitable by attackers?
Yes, attackers can exploit CVE-2026-61866 by providing malformed JNG files.