CVE-2026-23874

Vulnerability

CVE-2026-23874

ImageMagick: ImageMagick: Denial of Service via infinite recursion in MSL <write> command

ecosystem: redhat:6, redhat:7

A flaw was found in ImageMagick. A local user could exploit this vulnerability by providing a specially crafted Magick Scripting Language (MSL) file. This file, when processed, could trigger infinite recursion within the `<write>` command, leading to a stack overflow. Successful exploitation results in a Denial of Service (DoS) condition, making the application unavailable.

References
severityM
Moderate

type: vendor

source: secalert@redhat.com

CVSS3.1
5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AVLocal
ACLow
PRLow
UINone
SNot Changed
CNone
INone
AHigh

source: secalert@redhat.com

 CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

source: secalert@redhat.com

published: 2026-01-20 00:52:52

modified: 2026-01-20 03:46:02

Detection

redhat:6
CVE-2026-23874

redhat-vex

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-els:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-extras-including-unpatched:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-including-unpatched:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-supplementary:bed973f4-9cfe-9d6b-4efd-5501f715a543

redhat:7
CVE-2026-23874

redhat-vex

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-extras-including-unpatched:70e434bb-f93d-f0a0-34a8-8b2bd896644e

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-including-unpatched:70e434bb-f93d-f0a0-34a8-8b2bd896644e

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-supplementary:70e434bb-f93d-f0a0-34a8-8b2bd896644e

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub Logo IconGitHub