CVE-2026-93586: ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-56
Event History
Frequently Asked Questions
Which ImageMagick releases are affected and which releases contain the fix?
ImageMagick releases before 7.1.2-31 and before 6.9.13-56 are affected. The issue is fixed in 7.1.2-31 and 6.9.13-56.
What impact should be expected if this vulnerability is exploited?
The stated impact is limited to availability, such as a crash of the affected process. No confidentiality or integrity impact is identified.
What access does an attacker need to exploit this issue?
The CVSS vector indicates local attack access and high attack complexity, with no privileges or user interaction required.