PT-2026-76337 · Julia · Imagemagick Jll

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

In ReadSTEGANOImage() (coders/stegano.c), the watermark Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service.
Direct leak of 13512 byte(s) in 1 object(s) allocated from:
  #0 0x7f5c11e27887 in  interceptor malloc ../../../../src/libsanitizer/asan/asan malloc linux.cpp:145
  #1 0x55cdc38f65c4 in AcquireMagickMemory MagickCore/memory.c:536
  #2 0x55cdc38f65eb in AcquireCriticalMemory MagickCore/memory.c:612
  #3 0x55cdc3899e91 in AcquireImage MagickCore/image.c:154

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-946

Affected Products

Imagemagick Jll