CVE-2026-25799
Description
A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A logic error in the YUV sampling factor validation allows an invalid sampling factor to bypass security checks. This can trigger a division-by-zero error during image loading, leading to a reliable Denial of Service (DoS) for an affected system when processing a specially crafted image.
Statement
This MODERATE impact vulnerability in ImageMagick can lead to a denial-of-service. A logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks, triggering a division-by-zero during image loading. This affects ImageMagick as shipped in Red Hat Enterprise Linux 6 ELS and 7 ELS.
Mitigation
To mitigate this issue, avoid processing untrusted or unknown image files with ImageMagick. Limiting the exposure of ImageMagick to untrusted input sources can reduce the risk of exploitation.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.3 | 7.5 | 5.3 |
| Attack Vector | Network | Network | Network |
| Attack Complexity | Low | Low | Low |
| Privileges Required | None | None | None |
| User Interaction | None | None | None |
| Scope | Unchanged | Unchanged | Unchanged |
| Confidentiality | None | None | None |
| Integrity Impact | None | None | None |
| Availability Impact | Low | High | Low |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
A Divide by Zero results in a crash.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.