Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 NuGet

ImageMagick: Heap overflow in sun decoder on 32-bit systems may result in out of bounds write

GHSA-6j5f-24fw-pqp4 · CVE-2026-25897

Published · Modified

Description

An Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write.

=================================================================
==1967675==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xf190b50e at pc 0x5eae8777 bp 0xffb0fdd8 sp 0xffb0fdd0
WRITE of size 1 at 0xf190b50e thread T0

Ready to move

Start Securing

Free, no credit card | First findings in minutes