PT-2026-76367 · Julia · Imagemagick Jll

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
A heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed.
SUMMARY: AddressSanitizer: heap-use-after-free MagickCore/image.c:1195 in DestroyImage
Shadow bytes around the buggy address:
 0x0a4e80007450: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
 0x0a4e80007460: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
 0x0a4e80007470: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
 0x0a4e80007480: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
 0x0a4e80007490: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
=>0x0a4e800074a0: fd fd fd fd fd fd fd fd fd fd[fd]fd fd fd fd fd
 0x0a4e800074b0: fd fd fd fd fd fd fd fd fd fa fa fa fa fa fa fa
 0x0a4e800074c0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
 0x0a4e800074d0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
 0x0a4e800074e0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
 0x0a4e800074f0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-976

Affected Products

Imagemagick Jll