yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-56365
Component Overview
Vulnerability Overview
Name
CVE-2026-56365
Source
NVD (
link
)
Debian (
link
)
Description
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
CWEs
CWE-401
Published Date
Jun 30, 2026
Updated Date
Jul 2, 2026
Workaround
-
Advisories
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x928-4434-crqj
Vendor Advisory
https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-png-encoder-via-mng-image-writing
Third Party Advisory
Analysis
#
Affected Component
Analysis
imagemagick
Exploitable
Vulnerability Ratings
#
6.3
CVSSv4
3.7
CVSSv31
5.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
imagemagick
buildroot
2025.02.x
7.1.2-26
Not Affected
imagemagick
buildroot
master
7.1.2-26
Not Affected
imagemagick
openwrt
master
7.1.2.29-r1
Not Affected
imagemagick
openwrt
openwrt-25.12
7.1.2.1-r1
Not Affected
imagemagick
yocto
master
7.1.2-29
Not Affected
imagemagick
yocto
scarthgap
7.1.1-47
Exploitable