CVE-2026-23952

Vulnerability

CVE-2026-23952

ImageMagick: ImageMagick: Denial of Service via processing of MSL comment tags

ecosystem: redhat:6, redhat:7

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.

References
severityM
Moderate

type: vendor

source: secalert@redhat.com

CVSS3.1
6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AVNetwork
ACLow
PRLow
UINone
SNot Changed
CNone
INone
AHigh

source: secalert@redhat.com

 CWE
CWE-476

NULL Pointer Dereference

source: secalert@redhat.com

published: 2026-01-22 00:32:52

modified: 2026-02-27 16:36:27

Detection

redhat:6
CVE-2026-23952

redhat-vex

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-els:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-extras-including-unpatched:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-including-unpatched:bed973f4-9cfe-9d6b-4efd-5501f715a543

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-6-supplementary:bed973f4-9cfe-9d6b-4efd-5501f715a543

redhat:7
CVE-2026-23952

redhat-vex

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-extras-including-unpatched:70e434bb-f93d-f0a0-34a8-8b2bd896644e

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-including-unpatched:70e434bb-f93d-f0a0-34a8-8b2bd896644e

OR

unfixedOut of support scope

 

ImageMagick

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-c++-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-devel

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-doc

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick-perl

package type: binary

type: version
unfixedOut of support scope

 

ImageMagick

package type: source

type: version

tag: rhel-7-supplementary:70e434bb-f93d-f0a0-34a8-8b2bd896644e

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub Logo IconGitHub