CVE-2026-61870: ImageMagick before 7.1.2-26 Memory Leak via VIFF Encoder
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.6+deb12u13Fixed in 8:7.1.1.43+dfsg1-1+deb13u12Fixed in 8:7.1.2.31+dfsg1-1 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61870?
The severity of CVE-2026-61870 is classified as low with a score of 2.9.
How do I fix CVE-2026-61870?
To mitigate CVE-2026-61870, upgrade ImageMagick to version 7.1.2-26 or later.
What does CVE-2026-61870 affect?
CVE-2026-61870 affects ImageMagick versions prior to 7.1.2-26.
What type of vulnerability is CVE-2026-61870?
CVE-2026-61870 is a memory leak vulnerability in the VIFF encoder of ImageMagick.
How can CVE-2026-61870 be exploited?
CVE-2026-61870 can be exploited by attackers through specially crafted VIFF images that trigger memory allocation failures.