CVE-2026-30931
C# vulnerability analysis and mitigation

Overview

CVE-2026-30931 is a heap-based buffer overflow vulnerability in ImageMagick's UHDR (Ultra HDR) encoder, caused by integer truncation that enables an out-of-bounds write. It affects all ImageMagick versions prior to 7.1.2-16, as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9, 2026, by researcher linkeLi0421, and patched the same day (GitHub Advisory). Red Hat assigned a CVSS v3.1 score of 7.8 (High), while the GitHub/ENISA advisory scores it at 6.8 (Moderate) (Red Hat, Github Advisory).

Technical details

The root cause is an integer truncation flaw (CWE-190) in the UHDR encoder that leads to a heap-based buffer overflow (CWE-122). When a value is truncated during encoding, the resulting miscalculation allows a write operation to exceed the bounds of a heap-allocated buffer, as confirmed by AddressSanitizer output showing a WRITE of size 1 at an out-of-bounds heap address (0x521000039500) (GitHub Advisory). The attack vector is local, requiring low privileges (per Red Hat's scoring) or no privileges (per GitHub's scoring), with no user interaction needed (Red Hat, Github Advisory). No public proof-of-concept exploit code has been identified.

Impact

Successful exploitation can result in denial of service by crashing the ImageMagick process, and potentially information disclosure through the out-of-bounds memory write. The GitHub advisory also notes a low integrity impact due to the ability to write arbitrary data to heap memory. Because the attack is local in scope, the risk of direct remote exploitation is limited, but systems that process user-supplied images via ImageMagick (e.g., web servers, media pipelines) could be indirectly exposed (Red Hat, Github Advisory).

Mitigation and workarounds

Upgrade ImageMagick to version 7.1.2-16 or later, which contains the fix for this vulnerability (GitHub Advisory, Red Hat Bugzilla). Users of the Magick.NET NuGet wrapper should upgrade to version 14.10.4 or later (Github Advisory). As a temporary workaround for systems that cannot be immediately patched, restrict local user access to ImageMagick, limit processing of untrusted UHDR image files, and apply least-privilege principles to accounts running ImageMagick processes.

Community reactions

The vulnerability was reported by researcher linkeLi0421 and published by ImageMagick maintainer dlemstra on March 9, 2026 (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). Downstream Linux distributions including Debian and SUSE issued advisories and updates, and WAGO published a CSAF advisory referencing the CVE. Community reaction has been limited given the moderate severity and local-only attack vector.

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p5rm-jg5c-8c77MEDIUM6.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesJul 24, 2026
CVE-2026-62946MEDIUM5.1
  • C# logoC#
  • Magick.NET-Q16-AnyCPU
NoYesJul 24, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • Magick.NET-Q16-HDRI-OpenMP-arm64
NoYesJul 24, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q16-OpenMP-arm64
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • @aws-cdk/aws-codebuild
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management