Impact
ImageMagick releases a private object when reading a TXT image file that contains a texture attribute. If the subsequent GetTypeMetrics call fails, that object is never freed, causing the process to leak memory each time the file is parsed. The leak does not disclose or modify data; it simply consumes available RAM, which over repeated usage can exhaust system memory, destabilize the ImageMagick application, and potentially affect the host operating system.
Affected Systems
All installations of the ImageMagick image processing suite with releases older than 7.1.2‑15 in the 7.x branch or older than 6.9.13‑40 in the 6.x branch. Those versions are affected by the memory‑leak flaw when processing TXT files that include texture attributes.
Risk and Exploitability
The vulnerability can be exploited by forcing the target system to parse crafted TXT files containing a texture attribute. An attacker would need to supply such a file to a system that processes untrusted image data. The EPSS score of <1 % suggests that publicly available, automated exploitation is currently unlikely, and the flaw is not listed in CISA’s KEV catalogue. However, repeated or batch processing of malicious files can lead to memory exhaustion, presenting a moderate‑to‑high risk of denial of service. The CVSS score of 6.9 reflects these conditions.
OpenCVE Enrichment
Debian DLA
Debian DSA