DNA View

CVE-2026-25898

Medium
Low Medium High Critical
6.5
CVSS Score
Published: Feb 24, 2026
Last Modified: Feb 25, 2026

Vulnerability Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
L
Integrity
N
Availability
L

Available Security Patches

3 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
SUSE

CVE-2026-25898

CVE-2026-25898

Severity
Unknown
Released
Mar 05, 2026
Security Update
Canonical (Ubuntu)

USN-8069-1

USN-8069-1: ImageMagick vulnerabilities

Severity
Unknown
Released
Mar 04, 2026
Security Update

Severity Details

6.5
out of 10.0
Medium

Weakness Type (CWE)

CWE-125 Top 25 #11

Out-of-bounds Read

Description
The product reads data past the end, or before the beginning, of the intended buffer.
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
February 24, 2026