CVE-2022-20309
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-20309 is a vulnerability discovered in ImageMagick versions before 7.0.11 and before 6.9.12. The vulnerability was published on May 11, 2021, and affects the visual effects processing functionality of the software (Ubuntu CVE).

Technical details

The vulnerability exists in the WaveImage() function of MagickCore/visual-effects.c, where a division by zero condition can be triggered through a specially crafted image file. The vulnerability has been assigned a CVSS 3.1 Base Score of 7.5 (High), with attack vector being Network, attack complexity Low, requiring no privileges or user interaction, and affecting system availability (Ubuntu CVE).

Impact

When exploited, this vulnerability primarily affects system availability. If a user or automated system using ImageMagick is tricked into opening a specially crafted image file, an attacker could crash the application, causing a denial of service (Ubuntu Security Notice).

Mitigation and workarounds

The vulnerability has been fixed in multiple Ubuntu releases through security updates. Users are advised to update their ImageMagick packages to the patched versions. For Ubuntu 22.10, the fixed version is 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, for Ubuntu 20.04 LTS the fixed version is 8:6.9.10.23+dfsg-2.1ubuntu11.9, and for other supported versions, corresponding security updates are available (Ubuntu Security Notice).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-65622MEDIUM5.4
  • PHPPHP
  • snipe-it
NoYesDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management