Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.1 NuGet

ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds

GHSA-26qp-ffjh-2x4v · CVE-2026-34238

Published · Modified

Description

An integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write.

==1551685==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xea2fb818 at pc 0x56cbc42a bp 0xffc4ce48 sp 0xffc4ce38
WRITE of size 8 at 0xea2fb818 thread T0

Ready to move

Start Securing

Free, no credit card | First findings in minutes