CVE-2025-53015
published 2025-07-14CVE-2025-53015: ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.71%
49.3th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:7.1.1.47+dfsg1-2 (forky) | imagemagick 8:7.1.1.47+dfsg1-2 (forky) |
| imagemagick | imagemagick | < 7.1.2-0 | 7.1.2-0 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u1 | 8:7.1.1.43+dfsg1-1+deb13u1 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.47+dfsg1-2 | 8:7.1.1.47+dfsg1-2 |
| imagemagick | imagemagick | >= 7.1.1-7 < 7.1.2-0 | 7.1.2-0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ImageMagick: ImageMagick unbounded loop
vendor_redhat·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CWE-835 ImageMagick: ImageMagick unbounded loop
ImageMagick: ImageMagick unbounded loop
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
An unbounded execution loop has been discovered in ImageMagick. Given a maliciously crafted XMP file an attacker can trigger this vulnerability to cause a process hang.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
Package: ImageMagick (Red Ha
Debian
CVE-2025-53015: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2025·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 8:7.1.1.47+dfsg1-2)
sid: resolved (fixed in 8:7.1.1.47+dfsg1-2)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u1)
OSV
ImageMagick has XMP profile write that triggers hang due to unbounded loop
osv·2025-07-23
CVE-2025-53015 [HIGH] ImageMagick has XMP profile write that triggers hang due to unbounded loop
ImageMagick has XMP profile write that triggers hang due to unbounded loop
### Summary
Infinite lines occur when writing during a specific XMP file conversion command
### Details
```
#0 GetXmpNumeratorAndDenominator (denominator=, numerator=, value=) at MagickCore/profile.c:2578
#1 GetXmpNumeratorAndDenominator (denominator=, numerator=, value=720000000000000) at MagickCore/profile.c:2564
#2 SyncXmpProfile (image=image@entry=0x555555bb9ea0, profile=0x555555b9d020) at MagickCore/profile.c:2605
#3 0x00005555555db5cf in SyncImageProfiles (image=image@entry=0x555555bb9ea0) at MagickCore/profile.c:2651
#4 0x0000555555798d4f in WriteImage (image_info=image_info@entry=0x555555bc2050, image=image@entry=0x555555bb9ea0, exception=exception@entry=0x555555b7bea0) at MagickCore/constitute.c:1288
#5 0x
GHSA
ImageMagick has XMP profile write that triggers hang due to unbounded loop
ghsa·2025-07-23
CVE-2025-53015 [HIGH] CWE-835 ImageMagick has XMP profile write that triggers hang due to unbounded loop
ImageMagick has XMP profile write that triggers hang due to unbounded loop
### Summary
Infinite lines occur when writing during a specific XMP file conversion command
### Details
```
#0 GetXmpNumeratorAndDenominator (denominator=, numerator=, value=) at MagickCore/profile.c:2578
#1 GetXmpNumeratorAndDenominator (denominator=, numerator=, value=720000000000000) at MagickCore/profile.c:2564
#2 SyncXmpProfile (image=image@entry=0x555555bb9ea0, profile=0x555555b9d020) at MagickCore/profile.c:2605
#3 0x00005555555db5cf in SyncImageProfiles (image=image@entry=0x555555bb9ea0) at MagickCore/profile.c:2651
#4 0x0000555555798d4f in WriteImage (image_info=image_info@entry=0x555555bc2050, image=image@entry=0x555555bb9ea0, exception=exception@entry=0x555555b7bea0) at MagickCore/constitute.c:1288
#5 0x
OSV
CVE-2025-53015: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion command. Version 7.1.2-0 fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [fedora-42]
bugzilla·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [fedora-42]
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases
Bugzilla
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-9]
bugzilla·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-9]
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-2d971fc3b0 (ImageMagick-6.9.13.49-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d971fc3b0
---
FEDORA-EPEL-2026-fb9a9ab1e9 has been push
Bugzilla
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-8]
bugzilla·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-8]
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-2d971fc3b0 (ImageMagick-6.9.13.49-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d971fc3b0
---
FEDORA-EPEL-2026-fb9a9ab1e9 has been push
Bugzilla
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-10]
bugzilla·2025-07-14·CVSS 7.5
CVE-2025-53015 [HIGH] CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-10]
CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-1daced0e85 (ImageMagick-7.1.2.27-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1daced0e85
---
FEDORA-2026-63fca288d6 (ImageMagick
2025-07-14
Published