CVE-2026-25967: ImageMagick: Stack buffer overflow in FTXT reader via oversized integer field
A stack-based buffer overflow exists in the ImageMagick FTXT image reader. A crafted FTXT file can cause out-of-bounds writes on the stack, leading to a crash.
=================================================================
==3537074==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffee4850ef0 at pc 0x5607c408fb33 bp 0x7ffee484fe50 sp 0x7ffee484fe40
WRITE of size 1 at 0x7ffee4850ef0 thread T0
References
- github.com/ImageMagick/ImageMagick
- github.com/ImageMagick/ImageMagick/commit/9afe96cc325da1e4349fbd7418675af2f8708c10
- github.com/ImageMagick/ImageMagick/security/advisories/GHSA-72hf-fj62-w6j4
- github.com/advisories/GHSA-72hf-fj62-w6j4
- github.com/dlemstra/Magick.NET/releases/tag/14.10.3
- nvd.nist.gov/vuln/detail/CVE-2026-25967
Code Behaviors & Features
Detect and mitigate CVE-2026-25967 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →