ImageMagick Heap-Buffer-Overflow Read Vulnerability in GetPixelIndex via OpenPixelCache Metadata Desynchronization

Vulnerability

A heap-buffer-overflow read vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. This vulnerability arises in the GetPixelIndex function, where the OpenPixelCache method updates image channel metadata before allocating memory for the pixel cache. Attackers can exploit this flaw by causing memory and disk allocation failures, leading to a heap-buffer-overflow read that affects any writer using GetPixelIndex.

Impact

Exploitation of this vulnerability causes a heap-buffer-overflow read, which can lead to memory corruption and potentially allow for arbitrary code execution.

Remediation

Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.

Added: Jul 8, 2026, 2:33 PM
Updated: Jul 8, 2026, 2:33 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
4.1
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.