CVE-2026-25794
ImageMagick ImageMagick, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 취약점
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or potentially lead to an out of bounds heap write. Version 7.1.2-15 contains a patch.
- 대응 우선순위
- 점검
- CVSS
- 8.2
- EPSS
- 0.42% 백분위 34.6% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.02.24