CVE-2026-56363 Details
Description
ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application crash.
A division by zero vulnerability has been identified in ImageMagick versions prior to 7.1.2-22 and 6.9.13-47. This vulnerability arises in the processing of binomial kernels, where an attacker can supply a large kernel value that causes an integer overflow. The overflow leads to a division by zero, causing the application to crash, thus creating a denial-of-service condition.
Users can upgrade to ImageMagick versions 7.1.2-22 or 6.9.13-47 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vf33-6r7x-66xx | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/imagemagick-division-by-zero-in-binomial-kernel-processing | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| imagemagick imagemagick | < 6.9.13-47 >= 7.0.0-0, < 7.1.2-22 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |