CVE-2026-64685: ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-27
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64685?
The severity of CVE-2026-64685 is medium with a score of 5.3.
How do I fix CVE-2026-64685?
To fix CVE-2026-64685, update ImageMagick to version 7.1.2-27 or later.
What is the impact of CVE-2026-64685?
CVE-2026-64685 can lead to a heap buffer over-read when processing specially crafted BGR images.
Which versions of ImageMagick are affected by CVE-2026-64685?
ImageMagick versions prior to 7.1.2-27 are affected by CVE-2026-64685.
Is user input required for CVE-2026-64685 to be exploited?
No, CVE-2026-64685 does not require user interaction to be exploited.