CVE-2025-46393
published 2025-04-23CVE-2025-46393: In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.39%
31.9th percentile
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.1.46+dfsg1-1 (forky) | imagemagick 8:7.1.1.46+dfsg1-1 (forky) |
| imagemagick | imagemagick | < 7.1.1-44 | 7.1.1-44 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u1 | 8:7.1.1.43+dfsg1-1+deb13u1 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.46+dfsg1-1 | 8:7.1.1.46+dfsg1-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-46393: In multispectral MIFF image processing in ImageMagick before 7
osv·2025-04-23·CVSS 5.3
CVE-2025-46393 [MEDIUM] CVE-2025-46393: In multispectral MIFF image processing in ImageMagick before 7
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
GHSA
GHSA-f57x-prr8-55vv: In multispectral MIFF image processing in ImageMagick before 7
ghsa_unreviewed·2025-04-23
CVE-2025-46393 [LOW] CWE-131 GHSA-f57x-prr8-55vv: In multispectral MIFF image processing in ImageMagick before 7
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
Red Hat
ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing
vendor_redhat·2025-04-23·CVSS 2.9
CVE-2025-46393 [LOW] CWE-131 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing
ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
A flaw was found the inImageMagick package. In multispectral MIFF image processing in ImageMagick, packet_size is mishandled. This issue is related to the rendering of all channels in an arbitrary order.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: Ima
Debian
CVE-2025-46393: imagemagick - In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_si...
vendor_debian·2025·CVSS 2.9
CVE-2025-46393 [LOW] CVE-2025-46393: imagemagick - In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_si...
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 8:7.1.1.46+dfsg1-1)
sid: resolved (fixed in 8:7.1.1.46+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-8]
bugzilla·2025-04-24·CVSS 5.3
CVE-2025-46393 [MEDIUM] CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-8]
CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-8]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2361888
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-2d971fc3b0 (ImageMagick-6.9.13.49-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d971fc3b0
---
FEDORA-EPEL-2026-fb9a9ab1e9 (ImageMagick-6.9.13.49-1.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedor
Bugzilla
CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-9]
bugzilla·2025-04-24·CVSS 5.3
CVE-2025-46393 [MEDIUM] CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-9]
CVE-2025-46393 ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing [epel-9]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2361888
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-2d971fc3b0 (ImageMagick-6.9.13.49-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d971fc3b0
---
FEDORA-EPEL-2026-fb9a9ab1e9 has been pushed to the Fedora EPEL 8 testing repository.
You can provide feedback for this update
2025-04-23
Published