Impact
ImageMagick releases before 7.1.2-26 and 6.9.13-51 contain a memory leak in the log colorspace transformation. When the conversion operation fails, a small amount of memory is not released, which results in improper resource management (CWE‑401) and incomplete deallocation (CWE‑772). This deficiency can cause gradual memory exhaustion if the failure scenario is repeated frequently.
Affected Systems
The vulnerability affects all ImageMagick installations provided by ImageMagick, including all releases prior to 7.1.2-26 in the 7.x series and prior to 6.9.13-51 in the 6.x series. Any system that processes images through these libraries may be impacted, independent of platform.
Risk and Exploitability
The CVSS score of 2.1 indicates a low severity, and the EPSS score of less than 1% suggests a minimal chance of exploitation. This issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could repeatedly submit images that trigger to slowly deplete system memory, potentially degrading availability if a resource limit is breached. No public exploit has been documented as of the latest information.
OpenCVE Enrichment
Debian DLA