Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.8

ImageMagick: Large Image Can Cause Data Corruption

CVE-2026-30937 GHSA-qpg4-j99f-8xcg
Summary

A security issue in ImageMagick's image processing software can cause data corruption when handling extremely large images. This could potentially lead to loss of data or even control of the affected system. Update to the latest version of ImageMagick to fix this issue.

What to do
  • Update magick.net-q16-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-anycpu to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-arm64 to version 14.10.4.
  • Update magick.net-q16-hdri-x64 to version 14.10.4.
  • Update magick.net-q16-hdri-x86 to version 14.10.4.
  • Update magick.net-q16-openmp-arm64 to version 14.10.4.
  • Update magick.net-q16-openmp-x64 to version 14.10.4.
  • Update magick.net-q16-openmp-x86 to version 14.10.4.
  • Update magick.net-q16-arm64 to version 14.10.4.
  • Update magick.net-q16-x64 to version 14.10.4.
  • Update magick.net-q16-x86 to version 14.10.4.
  • Update magick.net-q16-hdri-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-anycpu to version 14.10.4.
  • Update magick.net-q8-openmp-arm64 to version 14.10.4.
  • Update magick.net-q8-openmp-x64 to version 14.10.4.
  • Update magick.net-q8-arm64 to version 14.10.4.
  • Update magick.net-q8-x64 to version 14.10.4.
  • Update magick.net-q8-x86 to version 14.10.4.
Affected software
VendorProductAffected versionsFix available
magick.net-q16-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-anycpu <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-arm64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x64 <= 14.10.4 14.10.4
magick.net-q16-hdri-x86 <= 14.10.4 14.10.4
magick.net-q16-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x64 <= 14.10.4 14.10.4
magick.net-q16-openmp-x86 <= 14.10.4 14.10.4
magick.net-q16-arm64 <= 14.10.4 14.10.4
magick.net-q16-x64 <= 14.10.4 14.10.4
magick.net-q16-x86 <= 14.10.4 14.10.4
magick.net-q16-hdri-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-anycpu <= 14.10.4 14.10.4
magick.net-q8-openmp-arm64 <= 14.10.4 14.10.4
magick.net-q8-openmp-x64 <= 14.10.4 14.10.4
magick.net-q8-arm64 <= 14.10.4 14.10.4
magick.net-q8-x64 <= 14.10.4 14.10.4
magick.net-q8-x86 <= 14.10.4 14.10.4
Original title
ImageMagick has heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation
Original description
A 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of bounds heap write can occur.

```
=================================================================
==741961==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x5020000083dc at pc 0x56553b4c4245 bp 0x7ffd9d20fef0 sp 0x7ffd9d20fee0
WRITE of size 1 at 0x5020000083dc thread T0
```
nvd CVSS3.1 6.8
Vulnerability type
CWE-122 Heap-based Buffer Overflow
CWE-190 Integer Overflow
Published: 12 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026