CVE-2026-93589: ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder
ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.1.2-31 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.9.13-56
Event History
Frequently Asked Questions
Which ImageMagick versions are affected and which versions contain the fix?
ImageMagick versions before 7.1.2-31 are affected, as are 6.x versions before 6.9.13-56. The issue is fixed in 7.1.2-31 and 6.9.13-56.
What input is required to trigger the denial of service?
An image being encoded through the FLIF encoder must contain an incorrect ticks-per-second value. Processing that value can cause a division by zero and crash the encoder.
What is the impact of successful exploitation?
Successful exploitation crashes the FLIF encoder, causing a denial of service. The provided severity vector indicates no confidentiality or integrity impact.