Logo
vulnerabilityCVE-2026-25966
Name
CVE-2026-25966
Source
NVD ( link)Debian ( link)
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" security policy includes a rule intended to prevent reading/writing from standard streams. However, ImageMagick also supports fd:<n> pseudo-filenames (e.g., fd:0, fd:1). Prior to versions 7.1.2-15 and 6.9.13-40, this path form is not blocked by the secure policy templates, and therefore bypasses the protection goal of "no stdin/stdout." Versions 7.1.2-15 and 6.9.13-40 contain a patch by including a change to the more secure policies by default. As a workaround, add the change to one's security policy manually.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
imagemagick
Patched

Vulnerability Ratings#


5.9
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
7.1.2-23
Not Affected
buildroot
master
7.1.2-23
Not Affected
openwrt
master
7.1.2.21-r1
Not Affected
openwrt
openwrt-25.12
7.1.2.1-r1
Not Affected
yocto
kirkstone
7.0.10-62
Exploitable
yocto
master
7.1.2-25
Not Affected

Resolved with patches#


imagemagick (yocto:scarthgap)

#
Title
Author
Resolve
1
Block reading from fd: in our more secure policies by default
Dirk Lemstra <dirk@lemstra.org>
CVE-2026-25966