CVE-2021-3962
ImageMagick vulnerability analysis and mitigation

Overview

A heap-use-after-free vulnerability (CVE-2021-3962) was discovered in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. The vulnerability was specifically identified in the RelinquishDCMMemory function within the dcm.c file. This issue affects ImageMagick version 7.1.0-14 and was fixed in version 7.1.0-15 (ImageMagick Issue, Red Hat Bugzilla).

Technical details

The vulnerability is a heap-use-after-free issue that occurs in the RelinquishDCMMemory function within dcm.c. The bug manifests when attempting to access memory at address 0x60f000000580 after it has been freed. The issue was triggered during image conversion operations using specific parameters. The vulnerability was confirmed through ASAN (Address Sanitizer) testing, which revealed the exact location of the use-after-free condition (ImageMagick Issue).

Impact

When exploited, this vulnerability could lead to program crashes due to memory corruption. The issue manifests as a double free detection in tcache, which could potentially lead to denial of service conditions or possible code execution in certain circumstances (ImageMagick Issue).

Mitigation and workarounds

The issue was fixed in ImageMagick version 7.1.0-15 by moving the free operation to the correct position in the code. Users should upgrade to this version or later to address the vulnerability. It's worth noting that ImageMagick6 is not affected by this vulnerability (Red Hat Bugzilla, ImageMagick Commit).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61871MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-doc
NoYesJul 15, 2026
CVE-2026-61868MEDIUM6.3
  • ImageMagick logoImageMagick
  • ImageMagick-devel
NoYesJul 15, 2026
CVE-2026-66011MEDIUM4.8
  • ImageMagick logoImageMagick
  • cpe:2.3:a:imagemagick:imagemagick
NoYesJul 25, 2026
CVE-2026-61869LOW2.1
  • ImageMagick logoImageMagick
  • libMagickWand-6_Q16-1
NoYesJul 15, 2026
CVE-2026-61872LOW2
  • ImageMagick logoImageMagick
  • ImageMagick-perl
NoYesJul 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management