ImageMagick Stack Buffer Overflow Vulnerability in Morphology Kernel Parsing

Vulnerability

A stack buffer overflow vulnerability has been identified in ImageMagick's morphology kernel parsing functions, prior to versions 7.1.2-16 and 6.9.13-41. The issue arises because user-controlled kernel strings that exceed a certain length are copied into fixed-size stack buffers using memcpy, without proper bounds checking. This flaw leads to stack corruption.

Impact

Exploitation of this vulnerability causes stack corruption, which can potentially be exploited to execute arbitrary code.

Remediation

Users can upgrade to ImageMagick versions 7.1.2-16 or 6.9.13-41 to address this vulnerability.

Added: Mar 10, 2026, 7:49 AM
Updated: Mar 10, 2026, 7:49 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.3
exploitability
4.4
remediation
7.7
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.