CVE-2025-57803
published 2025-08-26CVE-2025-57803: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.79%
52.4th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm) |
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u4 (bookworm) |
| imagemagick | imagemagick | < 6.9.13-32 | 6.9.13-32 |
| imagemagick | imagemagick | < 6.9.13-32 | 6.9.13-32 |
| imagemagick | imagemagick | < 6.9.13-28 | 6.9.13-28 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u6 | 8:6.9.11.60+dfsg-1.3+deb11u6 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u7 | 8:6.9.11.60+dfsg-1.3+deb11u7 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u4 | 8:6.9.11.60+dfsg-1.6+deb12u4 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u5 | 8:6.9.11.60+dfsg-1.6+deb12u5 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u2 | 8:7.1.1.43+dfsg1-1+deb13u2 |
| imagemagick | imagemagick | >= 0 < 8:7.1.1.43+dfsg1-1+deb13u3 | 8:7.1.1.43+dfsg1-1+deb13u3 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.3+dfsg1-1 | 8:7.1.2.3+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:7.1.2.7+dfsg1-1 | 8:7.1.2.7+dfsg1-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm15 | 8:6.7.7.10-6ubuntu3.13+esm15 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10-6ubuntu3.13+esm16 | 8:6.7.7.10-6ubuntu3.13+esm16 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm14 | 8:6.8.9.9-7ubuntu5.16+esm14 |
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm15 | 8:6.8.9.9-7ubuntu5.16+esm15 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm6 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm6 |
| imagemagick | imagemagick | >= 0 < 8:6.9.7.4+dfsg-16ubuntu6.15+esm7 | 8:6.9.7.4+dfsg-16ubuntu6.15+esm7 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm4 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm4 |
| imagemagick | imagemagick | >= 0 < 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm5 | 8:6.9.10.23+dfsg-2.1ubuntu11.11+esm5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm4 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm4 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm5 | 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm3 | 8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
vendor_oracle8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
imagemagick vulnerabilities
osv·2025-11-20·CVSS 8.8
CVE-2025-57803 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick did not properly handle memory when
encoding BMP images. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue exists due to an incomplete fix for
CVE-2025-57803.
GHSA
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
ghsa·2025-10-28·CVSS 8.8
CVE-2025-62171 [HIGH] CWE-190 ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
## Summary
CVE-2025-57803 claims to be patched in ImageMagick 7.1.2-2, but **the fix is incomplete and ineffective**. The latest version **7.1.2-5 remains vulnerable** to the same integer overflow attack.
The patch added `BMPOverflowCheck()` but placed it **after** the overflow occurs, making it useless. A malicious 58-byte BMP file can trigger AddressSanitizer crashes and DoS.
**Affected Versions:**
- ImageMagick columns * bmp_info.bits_per_pixel; // OVERFLOW!
// Line 1121: Uses already-overflowed value
bytes_per_line = 4*((extent+31)/32);
// Line 1122: Checks the RESULT, not the multiplication
if (BMPOverflowCheck(bytes_per_line, image->rows) != MagickFalse)
ThrowReaderException(CorruptImageError, "InsufficientImageDataInFil
OSV
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
osv·2025-10-28·CVSS 8.8
CVE-2025-62171 [HIGH] ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
## Summary
CVE-2025-57803 claims to be patched in ImageMagick 7.1.2-2, but **the fix is incomplete and ineffective**. The latest version **7.1.2-5 remains vulnerable** to the same integer overflow attack.
The patch added `BMPOverflowCheck()` but placed it **after** the overflow occurs, making it useless. A malicious 58-byte BMP file can trigger AddressSanitizer crashes and DoS.
**Affected Versions:**
- ImageMagick columns * bmp_info.bits_per_pixel; // OVERFLOW!
// Line 1121: Uses already-overflowed value
bytes_per_line = 4*((extent+31)/32);
// Line 1122: Checks the RESULT, not the multiplication
if (BMPOverflowCheck(bytes_per_line, image->rows) != MagickFalse)
ThrowReaderException(CorruptImageError, "InsufficientImageDataInFil
OSV
CVE-2025-62171: ImageMagick is an open source software suite for displaying, converting, and editing raster image files
osv·2025-10-17·CVSS 8.8
CVE-2025-62171 [HIGH] CVE-2025-62171: ImageMagick is an open source software suite for displaying, converting, and editing raster image files
ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vu
OSV
imagemagick vulnerabilities
osv·2025-10-08·CVSS 8.8
CVE-2025-55298 [HIGH] imagemagick vulnerabilities
imagemagick vulnerabilities
Woojin Park, Hojun Lee, Yougin Won and Siyeon Han discovered that
ImageMagick did not properly sanitize image file names. An attacker could
possibly use this issue to cause a denial of service, obtain sensitive
information, or execute arbitrary code. (CVE-2025-55298)
Lumina Mescuwa discovered that ImageMagick did not properly handle memory
when encoding BMP images. An attacker could possibly use this issue to
cause ImageMagick to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2025-57803)
OSV
CVE-2025-57803: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2025-08-26·CVSS 8.8
CVE-2025-57803 [HIGH] CVE-2025-57803: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.
GHSA
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
ghsa·2025-08-26
CVE-2025-57803 [HIGH] CWE-122 ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
## Summary
A 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses `bytes_per_line` (stride) to a tiny value while the per-row writer still emits `3 × width` bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines.
- **Impact:** Attacker-controlled heap out-of-bounds (OOB) write during conversion **to BMP**.
- **Surface:** Typical upload → normalize/thumbnail → `magick ... out.bmp` workers.
- **32-bit:** **Vulnerable** (
OSV
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
osv·2025-08-26
CVE-2025-57803 [HIGH] ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
## Summary
A 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses `bytes_per_line` (stride) to a tiny value while the per-row writer still emits `3 × width` bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines.
- **Impact:** Attacker-controlled heap out-of-bounds (OOB) write during conversion **to BMP**.
- **Surface:** Typical upload → normalize/thumbnail → `magick ... out.bmp` workers.
- **32-bit:** **Vulnerable** (
Ubuntu
ImageMagick vulnerability
vendor_ubuntu·2025-11-20·CVSS 7.5
CVE-2025-62171 [HIGH] ImageMagick vulnerability
Title: ImageMagick vulnerability
Summary: ImageMagick could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that ImageMagick did not properly handle memory when
encoding BMP images. An attacker could possibly use this issue to cause
ImageMagick to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue exists due to an incomplete fix for
CVE-2025-57803.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ImageMagick: ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems
vendor_redhat·2025-10-17·CVSS 7.5
CVE-2025-62171 [HIGH] CWE-190 ImageMagick: ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems
ImageMagick: ImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems
ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912
Oracle
Oracle Oracle Communications Risk Matrix: Developer Infrastructure (ImageMagick) — CVE-2025-57803
vendor_oracle·2025-10-15·CVSS 8.8
CVE-2025-57803 [HIGH] Oracle Oracle Communications Risk Matrix: Developer Infrastructure (ImageMagick) — CVE-2025-57803
Oracle Oracle Communications Risk Matrix: Developer Infrastructure (ImageMagick) vulnerability
CVE: CVE-2025-57803
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2025-10-08·CVSS 7.5
CVE-2025-55298 [HIGH] ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
Woojin Park, Hojun Lee, Yougin Won and Siyeon Han discovered that
ImageMagick did not properly sanitize image file names. An attacker could
possibly use this issue to cause a denial of service, obtain sensitive
information, or execute arbitrary code. (CVE-2025-55298)
Lumina Mescuwa discovered that ImageMagick did not properly handle memory
when encoding BMP images. An attacker could possibly use this issue to
cause ImageMagick to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2025-57803)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
vendor_redhat·2025-08-26·CVSS 7.5
CVE-2025-57803 [HIGH] CWE-190 imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-2
Debian
CVE-2025-62171: imagemagick - ImageMagick is an open source software suite for displaying, converting, and edi...
vendor_debian·2025·CVSS 7.5
CVE-2025-62171 [HIGH] CVE-2025-62171: imagemagick - ImageMagick is an open source software suite for displaying, converting, and edi...
ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vu
Debian
CVE-2025-57803: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2025·CVSS 7.5
CVE-2025-57803 [HIGH] CVE-2025-57803: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u4)
bullseye: resolved (fixed in 8:6.9.1
No detection rules found.
No public exploits indexed.
https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmmhttps://github.com/dlemstra/Magick.NET/releases/tag/14.8.1https://lists.debian.org/debian-lts-announce/2025/09/msg00012.htmlhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm
2025-08-26
Published