yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-68618
Component Overview
Vulnerability Overview
Name
CVE-2025-68618
Source
NVD (
link
)
Debian (
link
)
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
CWEs
CWE-674
Published Date
Dec 30, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb
Patch
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637
Exploit
Analysis
#
Affected Component
Analysis
imagemagick
Patched
Vulnerability Ratings
#
5.3
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
imagemagick
buildroot
2025.02.x
7.1.2-23
Not Affected
imagemagick
buildroot
master
7.1.2-23
Not Affected
imagemagick
openwrt
master
7.1.2.21-r1
Not Affected
imagemagick
openwrt
openwrt-25.12
7.1.2.1-r1
Not Affected
imagemagick
yocto
kirkstone
7.0.10-62
Exploitable
imagemagick
yocto
master
7.1.2-25
Not Affected
Resolved with patches
#
imagemagick (yocto:scarthgap)
#
Title
Author
Resolve
1
Patch #1
Cristy <urban-warrior@imagemagick.org>
CVE-2025-68618