What is CVE-2026-64685?
CVE-2026-64685 affects ImageMagick versions prior to 7.1.2-27, where the BGR decoder misses an end-of-file check, potentially leading to a heap buffer over-read via a crafted image. Upgrading to version 7.1.2-27 or later is required to fix this issue.
Azərbaycanca: CVE-2026-64685, ImageMagick proqramının 7.1.2-27 versiyasından əvvəlki versiyalarını təsir edən boşluqdur. BGR dekoderində fayl sonu (end-of-file) yoxlamasının düzgün aparılmaması, xüsusi hazırlanmış şəkil vasitəsilə heap buffer over-read zəifliyinə səbəb ola bilər. Bu problemi aradan qaldırmaq üçün dərhal 7.1.2-27 və ya daha sonrakı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of ImageMagick are affected by CVE-2026-64685?
All versions of ImageMagick prior to 7.1.2-27 are affected by this vulnerability.
What is the root cause of CVE-2026-64685?
The vulnerability is caused by a missing end-of-file check in the BGR decoder.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.