Impact
ImageMagick contains a memory leak in the WriteMSLImage function of msl.c that fails to release resources allocated during encoding. The leak is triggered when processing MSL images, potentially leading to memory exhaustion and application crashes. This weakness is classified as CWE‑401 and CWE‑772 and could be leveraged by an attacker to degrade performance or bring the system to a failure state, compromising availability.
Affected Systems
All versions of ImageMagick older than 7.1.2-15 and 6.9.13-40 are susceptible. The affected product is the ImageMagick image processing library and supporting tools. The patch was introduced in those specific releases.
Risk and Exploitability
With a CVSS score of 5.3 the risk level is moderate, but the exploitation probability is very low as shown by an EPSS score of less than 1 % and the absence from the KEV catalogue. The vulnerability is likely exploitable only by a local user or privileged process that can feed crafted MSL images into the library; remote exploitation has not been documented. In environments where untrusted images are processed, the risk is elevated.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA