ImageMagick use-after-free in PDB decoder before 7.1.2-15
CVE-2026-56373 Published on July 10, 2026

ImageMagick - Use-After-Free Write in PDB Decoder
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-56373 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-56373 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-56373

stack.watch emails you whenever new vulnerabilities are published in ImageMagick or Canonical Ubuntu Linux. Just hit a watch button to start following.

 
 

Affected Versions

ImageMagick: ImageMagick: