CVE-2025-55154
published 2025-08-13CVE-2025-55154: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.97%
57.9th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm) |
| imagemagick | imagemagick | < 7.1.2-1 | 7.1.2-1 |
| imagemagick | imagemagick | < 6.9.13-27 | 6.9.13-27 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u6 | 8:6.9.11.60+dfsg-1.3+deb11u6 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u4 | 8:6.9.11.60+dfsg-1.6+deb12u4 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u2 | 8:7.1.1.43+dfsg1-1+deb13u2 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.1+dfsg1-1 | 8:7.1.2.1+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm14 | 8:6.7.7.10-6ubuntu3.13+esm14 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm13 | 8:6.8.9.9-7ubuntu5.16+esm13 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm5 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm3 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm3 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2 | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.1.2-1 | 7.1.2-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2025-09-18·CVSS 8.8
CVE-2025-55154 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick did not properly handle memory when
performing magnified size calculations. An attacker could possibly use this
issue to cause ImageMagick to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2025-55154)
Woojin Park, Hojun Lee, Youngin Won, and Siyeon Han discovered that
ImageMagick incorrectly handled creating thumbnail images for certain
dimensions. An attacker could possibly use this issue to cause ImageMagick
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2025-55212)
Lumina Mescuwa discovered that ImageMagick did not properly handle cloning
splay trees in the MagickCore library.
Red Hat
imagemagick: ImageMagick: integer overflows in MNG magnification
vendor_redhat·2025-08-13·CVSS 8.8
CVE-2025-55154 [HIGH] CWE-190 imagemagick: ImageMagick: integer overflows in MNG magnification
imagemagick: ImageMagick: integer overflows in MNG magnification
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
An integer overflow flaw has been discovered in ImageMagick. The magnified size calculations in ReadOneMNGIMage in coders/png.c are unsafe and can overflow, leading to memory corruption.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread inst
Debian
CVE-2025-55154: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2025·CVSS 8.8
CVE-2025-55154 [HIGH] CVE-2025-55154: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u4)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u6)
forky: resolved (fixed in 8:7.1.2.1+dfsg1-1)
sid: resolved (fixed in 8:7.1.2.1+dfsg1-1)
trixie: resolved (fixed in 8:7.1.1.43+dfsg1-1+deb13u2)
OSV
imagemagick vulnerabilities
osv·2025-09-18·CVSS 7.8
CVE-2025-55154 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick did not properly handle memory when
performing magnified size calculations. An attacker could possibly use this
issue to cause ImageMagick to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2025-55154)
Woojin Park, Hojun Lee, Youngin Won, and Siyeon Han discovered that
ImageMagick incorrectly handled creating thumbnail images for certain
dimensions. An attacker could possibly use this issue to cause ImageMagick
to crash, resulting in a denial of service. This issue only affected Ubuntu
24.04 LTS. (CVE-2025-55212)
Lumina Mescuwa discovered that ImageMagick did not properly handle cloning
splay trees in the MagickCore library. An attacker could possibly use this
issue to cause sanitized builds
GHSA
imagemagick: integer overflows in MNG magnification
ghsa·2025-08-25
CVE-2025-55154 [HIGH] CWE-190 imagemagick: integer overflows in MNG magnification
imagemagick: integer overflows in MNG magnification
## **Vulnerability Details**
The magnified size calculations in `ReadOneMNGIMage` (in `coders/png.c`) are unsafe and can overflow, leading to memory corruption.
The source snippet below is heavily abbreviated due to the size of the function, but hopefully the important points are captured.
```c
static Image *ReadOneMNGImage(MngReadInfo* mng_info,
const ImageInfo *image_info,ExceptionInfo *exception)
{
// Lots of stuff, this is effectively a state machine for the MNG rendering commands,
// skip to the point where we start processing the "MAGN" command.
if (memcmp(type,mng_MAGN,4) == 0)
{
png_uint_16
magn_first,
magn_last,
magn_mb,
magn_ml,
magn_mr,
magn_mt,
magn_mx,
magn_my,
magn_methx,
magn_methy;
// Details unimportant, but each o
OSV
imagemagick: integer overflows in MNG magnification
osv·2025-08-25
CVE-2025-55154 [HIGH] imagemagick: integer overflows in MNG magnification
imagemagick: integer overflows in MNG magnification
## **Vulnerability Details**
The magnified size calculations in `ReadOneMNGIMage` (in `coders/png.c`) are unsafe and can overflow, leading to memory corruption.
The source snippet below is heavily abbreviated due to the size of the function, but hopefully the important points are captured.
```c
static Image *ReadOneMNGImage(MngReadInfo* mng_info,
const ImageInfo *image_info,ExceptionInfo *exception)
{
// Lots of stuff, this is effectively a state machine for the MNG rendering commands,
// skip to the point where we start processing the "MAGN" command.
if (memcmp(type,mng_MAGN,4) == 0)
{
png_uint_16
magn_first,
magn_last,
magn_mb,
magn_ml,
magn_mr,
magn_mt,
magn_mx,
magn_my,
magn_methx,
magn_methy;
// Details unimportant, but each o
OSV
CVE-2025-55154: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2025-08-13·CVSS 7.8
CVE-2025-55154 [HIGH] CVE-2025-55154: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-9]
bugzilla·2025-08-13·CVSS 7.8
CVE-2025-55154 [HIGH] CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-9]
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-b12c038824 (ImageMagick-6.9.13.52-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b12c038824
---
FEDORA-EPEL-2026
Bugzilla
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-10]
bugzilla·2025-08-13·CVSS 7.8
CVE-2025-55154 [HIGH] CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-10]
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-1daced0e85 (ImageMagick-7.1.2.27-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1daced0e85
---
FEDORA-202
Bugzilla
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [fedora-42]
bugzilla·2025-08-13·CVSS 7.8
CVE-2025-55154 [HIGH] CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [fedora-42]
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-8]
bugzilla·2025-08-13·CVSS 7.8
CVE-2025-55154 [HIGH] CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-8]
CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-b12c038824 (ImageMagick-6.9.13.52-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b12c038824
---
FEDORA-EPEL-2026
2025-08-13
Published