Impact
The flaw is a memory leak in the MIFF encoder that triggers when a memory allocation fails during MIFF image processing. This leak can cause the ImageMagick service or application to consume increasing amounts of RAM until it becomes unresponsive or crashes, thereby denying service to legitimate workloads. The weakness is classified under CWE-401 (Unreleased Resource) and CWE-770 (Memory Allocation for Indeterminate Order),
Affected Systems
The vulnerability affects ImageMagick products before version 7.1.2-26 and before 6.9.13-51. Any deployment using the affected releases and processing MIFF images is at risk.
Risk and Exploitability
The CVSS score is 2.1 and the EPSS score is below 1%, indicating a low overall risk and a very low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. The most likely attack vector is the local or remote execution of a crafted MIFF file that forces ImageMagick to allocate memory and fail, leading to a leak. Because it does not expose sensitive data or privileges, the primary danger is service disruption rather than data compromise.
OpenCVE Enrichment
Debian DLA