Low [CVE-2026-56365] Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm6…
This low-severity Red Hat Linux advisory covers CVE-2026-56365 affecting Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat package: imagemagick.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
A flaw was found in ImageMagick. This issue is categorized as a memory leak (CWE-401).
While the flaw can exhaust system memory, it requires an application to process a specially crafted MNG image, limiting the attack surface in typical Red Hat deployments. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Weakness: CWE-401. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.
Affected products named by the advisory: Red Hat package: imagemagick.
- < 7.1.2-19
Official advisory · high-confidence parse· fetched 3 days ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 3 days ago·verify at source
Mitigation checklist
- To mitigate this use system controls (such as ulimit or container memory limits) to strictly cap the memory available to the ImageMagick process. This prevents a leak from crashing the wider system.
Official advisory · high-confidence parse· fetched 3 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.