CVE-2026-56364
ImageMagick has a Memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML
EPSS 0.12%
Description
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
How to fix CVE-2026-56364
To remediate CVE-2026-56364, upgrade the affected package to a fixed version below.
- Debian/imagemagick—upgrade to 8:7.1.1.43+dfsg1-1+deb13u11 or later
Is CVE-2026-56364 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8:7.1.1.43+dfsg1-1+deb13u11
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |