<Vulnerability name="CVE-2026-56368">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-06-24T11:53:20</PublicDate>
    <Bugzilla id="2492145" url="https://bugzilla.redhat.com/show_bug.cgi?id=2492145" xml:lang="en:us">
Imagemagick: ImageMagick - Memory Leak in Raw Pixel Data Coders
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.7</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</CVSS3ScoringVector>
    </CVSS3>
    <Details xml:lang="en:us" source="Mitre">
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in ImageMagick. This memory leak vulnerability exists in multiple coders that write raw pixel data, where allocated objects are not properly freed. A remote attacker can exploit this by processing specially crafted images, leading to memory exhaustion and a denial of service.
    </Details>
    <Statement xml:lang="en:us">
A memory leak exists in ImageMagick's raw pixel data coders. Processing specially crafted, untrusted images can exhaust system memory and cause a Denial of Service (DoS).
    </Statement>
    <Mitigation xml:lang="en:us">
Modify the ImageMagick security policy file (policy.xml, typically located in /etc/ImageMagick-7/ or /etc/ImageMagick-6/) to disable the processing of RAW pixel data formats.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>ImageMagick</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>ImageMagick</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-56368
https://nvd.nist.gov/vuln/detail/CVE-2026-56368
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc
https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders
    </References>
</Vulnerability>