CVE-2026-62946: ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.
Other sources
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Magick.NET-Q8-x86to a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
nuget/Magick.NET-Q8-AnyCPUto a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-x86to a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-x86to a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-HDRI-AnyCPUto a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
nuget/Magick.NET-Q16-AnyCPUto a version that resolves this vulnerability.Fixed in 14.15.0 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-52 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-27
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62946?
CVE-2026-62946 has a medium severity rating of 5.1.
What causes the vulnerability CVE-2026-62946?
CVE-2026-62946 is caused by an integer overflow when processing extremely large JNX files on 32-bit platforms.
How can I fix CVE-2026-62946?
To fix CVE-2026-62946, update to the latest secure version of Magick.NET that addresses the vulnerability.
Which software versions are affected by CVE-2026-62946?
CVE-2026-62946 affects various versions of Magick.NET including Q8-x86, Q8-AnyCPU, Q16-x86, Q16-HDRI-x86, Q16-HDRI-AnyCPU, and Q16-AnyCPU.
What could happen if CVE-2026-62946 is exploited?
Exploitation of CVE-2026-62946 could lead to a heap buffer overwrite, potentially allowing for arbitrary code execution.