PT-2026-76328 · Julia · Imagemagick Jll

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

NULL pointer dereference in MSL (Magick Scripting Language) parser when processing <comment> tag before any image is loaded.

Version

  • ImageMagick 7.x (tested on current main branch)
  • Commit: HEAD

Steps to Reproduce

Method 1: Using ImageMagick directly

bash
magick MSL:poc.msl out.png

Method 2: Using OSS-Fuzz reproduce

bash
python3 infra/helper.py build fuzzers imagemagick
python3 infra/helper.py reproduce imagemagick msl fuzzer poc.msl
Or run the fuzzer directly:
bash
./msl fuzzer poc.msl

Expected Behavior

ImageMagick should handle the malformed MSL gracefully and return an error message.

Actual Behavior

convert: MagickCore/property.c:297: MagickBooleanType DeleteImageProperty(Image *, const char *): Assertion `image != (Image *) NULL' failed.
Aborted

Root Cause Analysis

In coders/msl.c:7091, MSLEndElement() calls DeleteImageProperty() on msl info->image[n] when handling the </comment> end tag without checking if the image is NULL:
c
if (LocaleCompare((const char *) tag,"comment") == 0 )
 {
  (void) DeleteImageProperty(msl info->image[n],"comment"); // No NULL check
  ...
 }
When <comment> appears before any <read> operation, msl info->image[n] is NULL, causing the assertion failure in DeleteImageProperty() at property.c:297.

Impact

  • DoS: Crash via assertion failure (debug builds) or NULL pointer dereference (release builds)
  • Affected: Any application using ImageMagick to process user-supplied MSL files

Fuzzer

This issue was discovered using a custom MSL fuzzer:
cpp
#include <cstdint>
#include <Magick++/Blob.h>
#include <Magick++/Image.h>
#include "utils.cc"

extern "C" int LLVMFuzzerTestOneInput(const uint8 t *Data, size t Size)
{
 if (IsInvalidSize(Size))
  return(0);
 try
 {
  const Magick::Blob blob(Data, Size);
  Magick::Image image;
  image.magick("MSL");
  image.fileName("MSL:");
  image.read(blob);
 }
 catch (Magick::Exception)
 {
 }
 return(0);
}
This issue was found by Team FuzzingBrain @ Texas A&M University

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-937

Affected Products

Imagemagick Jll