CVE-2025-65955

MEDIUM

ImageMagick <7.1.2-9 & 6.9.13-34 - Memory Corruption

Title source: llm

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

Scores

CVSS v3 4.9
EPSS 0.0002
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-415 CWE-416
Status published

Affected Products (19)

imagemagick/imagemagick < 6.9.13-34
nuget/Magick.NET-Q16-AnyCPU NuGet
nuget/Magick.NET-Q16-HDRI-AnyCPU NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64 NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-x64 NuGet
nuget/Magick.NET-Q16-HDRI-arm64 NuGet
nuget/Magick.NET-Q16-HDRI-x64 NuGet
nuget/Magick.NET-Q16-HDRI-x86 NuGet
nuget/Magick.NET-Q16-OpenMP-arm64 NuGet
nuget/Magick.NET-Q16-OpenMP-x64 NuGet
nuget/Magick.NET-Q16-arm64 NuGet
nuget/Magick.NET-Q16-x64 NuGet
nuget/Magick.NET-Q16-x86 NuGet
nuget/Magick.NET-Q8-AnyCPU NuGet
nuget/Magick.NET-Q8-OpenMP-arm64 NuGet
... and 4 more

Timeline

Published Dec 02, 2025
Tracked Since Feb 18, 2026