
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30931 is a heap-based buffer overflow vulnerability in ImageMagick's UHDR (Ultra HDR) encoder, caused by integer truncation that enables an out-of-bounds write. It affects all ImageMagick versions prior to 7.1.2-16, as well as Magick.NET NuGet packages prior to version 14.10.4. The vulnerability was published on March 9, 2026, by researcher linkeLi0421, and patched the same day (GitHub Advisory). Red Hat assigned a CVSS v3.1 score of 7.8 (High), while the GitHub/ENISA advisory scores it at 6.8 (Moderate) (Red Hat, Github Advisory).
The root cause is an integer truncation flaw (CWE-190) in the UHDR encoder that leads to a heap-based buffer overflow (CWE-122). When a value is truncated during encoding, the resulting miscalculation allows a write operation to exceed the bounds of a heap-allocated buffer, as confirmed by AddressSanitizer output showing a WRITE of size 1 at an out-of-bounds heap address (0x521000039500) (GitHub Advisory). The attack vector is local, requiring low privileges (per Red Hat's scoring) or no privileges (per GitHub's scoring), with no user interaction needed (Red Hat, Github Advisory). No public proof-of-concept exploit code has been identified.
Successful exploitation can result in denial of service by crashing the ImageMagick process, and potentially information disclosure through the out-of-bounds memory write. The GitHub advisory also notes a low integrity impact due to the ability to write arbitrary data to heap memory. Because the attack is local in scope, the risk of direct remote exploitation is limited, but systems that process user-supplied images via ImageMagick (e.g., web servers, media pipelines) could be indirectly exposed (Red Hat, Github Advisory).
Upgrade ImageMagick to version 7.1.2-16 or later, which contains the fix for this vulnerability (GitHub Advisory, Red Hat Bugzilla). Users of the Magick.NET NuGet wrapper should upgrade to version 14.10.4 or later (Github Advisory). As a temporary workaround for systems that cannot be immediately patched, restrict local user access to ImageMagick, limit processing of untrusted UHDR image files, and apply least-privilege principles to accounts running ImageMagick processes.
The vulnerability was reported by researcher linkeLi0421 and published by ImageMagick maintainer dlemstra on March 9, 2026 (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it medium severity (Red Hat Bugzilla). Downstream Linux distributions including Debian and SUSE issued advisories and updates, and WAGO published a CSAF advisory referencing the CVE. Community reaction has been limited given the moderate severity and local-only attack vector.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."