Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. Magick.NET-Q16-OpenMP-arm64
  4. ›
  5. GHSA-3j4x-rwrx-xxj9

GHSA-3j4x-rwrx-xxj9: mageMagick has a possible use-after-free write in its PDB decoder

February 25, 2026

A use-after-free vulnerability exists in the PDB decoder that will use a stale pointer when a memory allocation fails and that could result in a crash or a single zero byte write.

==4033155==ERROR: AddressSanitizer: UNKNOWN SIGNAL on unknown address 0x000000000000 (pc 0x5589c1971b24 bp 0x7ffdcc7ae2d0 sp 0x7ffdcc7adb20 T0)
==4034812==ERROR: AddressSanitizer: heap-use-after-free on address 0x7f099e9f7800 at pc 0x5605d909ab20 bp 0x7ffe52045b50 sp 0x7ffe52045b40
WRITE of size 1 at 0x7f099e9f7800 thread T0

References

  • github.com/ImageMagick/ImageMagick
  • github.com/ImageMagick/ImageMagick/commit/168ffe18def968f886c023146a478897866fd621
  • github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9
  • github.com/advisories/GHSA-3j4x-rwrx-xxj9
  • github.com/dlemstra/Magick.NET/releases/tag/14.10.3

Code Behaviors & Features

Detect and mitigate GHSA-3j4x-rwrx-xxj9 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 14.10.3

Fixed versions

  • 14.10.3

Solution

Upgrade to version 14.10.3 or above.

Impact 3.7 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-416: Use After Free

Source file

nuget/Magick.NET-Q16-OpenMP-arm64/GHSA-3j4x-rwrx-xxj9.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:19:18 +0000.