Bug 2537935 (CVE-2026-93590)

Summary: CVE-2026-93590 ImageMagick: ImageMagick: Denial of Service via UHDR encoder policy bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in ImageMagick's UHDR encoder. This vulnerability allows a remote attacker to bypass resource policies by processing specially crafted UHDR images. The flaw occurs because the encoder fails to perform necessary policy checks during buffer allocation for image pixels, potentially leading to a Denial of Service (DoS) through excessive memory allocation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539115, 2539116    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 16:08:47 UTC
ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.