Impact
An ImageMagick policy bypass exists in the UHDR encoder, where pixel buffer allocation does not enforce policy checks during memory allocation. Attackers can craft special UHDR images that trigger uncontrolled memory allocation, potentially exhausting system resources and causing a denial of service. The weaknesses align with resource exhaustion (CWE-400) and incorrect buffer size calculation (CWE-131). Processing such an image would allow an attacker to consume large amounts of memory, leading to service interruption if the application does not handle it safely.
Affected Systems
All installations of ImageMagick before version 7.1.2‑31 are affected. The vendor/product is ImageMagick ImageMagick, and any instance running a vulnerable version remains susceptible.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog suggest limited current exploitation activity. Exploitation would require an environment that processes UHDR images through ImageMagick, typically a web service or user‑controlled input. The likely attack vector is an application that decodes or renders UHDR images, and the inference is that an attacker would need to supply a specially crafted UHDR image to trigger uncontrolled memory allocation, potentially causing denial‑of‑service. While no public exploit has been reported, the feasibility of denial of service makes prompt mitigation advisable.
OpenCVE Enrichment