CVE-2026-56368
C# 脆弱性の分析と軽減

概要

CVE-2026-56368 is a memory leak vulnerability in ImageMagick affecting multiple coders that write raw pixel data, where allocated objects are not properly freed after use. It affects ImageMagick versions before 7.1.2-15 (7.x branch) and before 6.9.13-40 (6.x branch). The vulnerability was published on June 24, 2026, and was originally disclosed via a GitHub Security Advisory (GHSA-wfx3-6g53-9fgc) credited to researcher ylwango613. It carries a CVSS v3.1 base score of 3.7 (Low) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, VulnCheck).

技術的な詳細

The vulnerability is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), where memory allocated during raw pixel data writing operations in multiple ImageMagick coders is never freed. Specifically, a direct leak of 160 bytes in one object has been identified as allocated but not released during the affected coder operations. An attacker can trigger this leak by submitting a specially crafted image file for processing — no authentication or user interaction is required, though exploitation requires high attack complexity (e.g., specific conditions or timing). The attack vector is network-based, meaning the vulnerability can be triggered remotely wherever ImageMagick processes user-supplied images (GitHub Advisory).

影響

Successful exploitation causes gradual memory exhaustion on the affected host, ultimately resulting in a denial of service condition. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. In environments where ImageMagick processes high volumes of user-supplied images (e.g., web applications, media pipelines), repeated triggering of the leak could degrade or crash the service over time (GitHub Advisory, VulnCheck).

軽減策と回避策

Users should upgrade to ImageMagick 7.1.2-15 or later (for the 7.x branch) or 6.9.13-40 or later (for the 6.x branch), which contain the fix for this memory leak. No configuration-based workarounds have been published. As an interim measure, operators can limit or sandbox ImageMagick's processing of untrusted images to reduce exposure until patching is feasible (GitHub Advisory, VulnCheck).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 C# 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-48109HIGH8.2
  • C#C#
  • messagepack
いいえはいJun 22, 2026
CVE-2026-54784HIGH7.4
  • C#C#
  • CoreWCF.Primitives
いいえはいJun 19, 2026
CVE-2026-54783HIGH7.4
  • C#C#
  • CoreWCF.Primitives
いいえはいJun 19, 2026
CVE-2026-56370NONE該当なし
  • C#C#
  • Magick.NET-Q16-HDRI-arm64
いいえはいJun 25, 2026
CVE-2026-56368NONE該当なし
  • C#C#
  • imagemagick
いいえはいJun 25, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者