Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0610

NIXPKGS-2026-0610
published on
Permalink CVE-2026-28688
4.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
updated 3 weeks, 4 days ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt removed package imagemagick6
  • @mweinelt removed package imagemagick6Big
  • @mweinelt removed package imagemagick6_light
  • @mweinelt removed package graphicsmagick-imagemagick-compat
  • @mweinelt removed package tests.pkg-config.defaultPkgConfigPackages.MagickWand
  • @mweinelt removed package tests.pkg-config.defaultPkgConfigPackages.ImageMagick
  • @mweinelt accepted
  • @mweinelt published on GitHub
ImageMagick has a heap use-after-free in the MSL encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap-use-after-free vulnerability exists in the MSL encoder, where a cloned image is destroyed twice. The MSL coder does not support writing MSL so the write capability has been removed. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

Affected products

ImageMagick
  • ==< 6.9.13-41
  • ==>= 7.0.0, < 7.1.2-16

Matching in nixpkgs

Package maintainers

https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xxw5-m53x-j38c