icon

We found results for “

CVE-2026-22770

Good to know:

icon
icon

Date: January 19, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS when the memory allocation fails. Version 7.1.2-13 contains a patch for the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Release of Invalid Pointer or Reference

CWE-763

Top Fix

icon

Upgrade Version

Upgrade to version magick.net-q8-x64 - 14.10.2;magick.net-q8-arm64 - 14.10.2;magick.net-q8-x86 - 14.10.2;magick.net-q8-openmp-x64 - 14.10.2;magick.net-q8-openmp-arm64 - 14.10.2;magick.net-q16-x64 - 14.10.2;magick.net-q16-arm64 - 14.10.2;magick.net-q16-x86 - 14.10.2;magick.net-q16-openmp-x64 - 14.10.2;magick.net-q16-openmp-arm64 - 14.10.2;magick.net-q16-hdri-x64 - 14.10.2;magick.net-q16-hdri-arm64 - 14.10.2;magick.net-q16-hdri-x86 - 14.10.2;magick.net-q16-hdri-openmp-x64 - 14.10.2;magick.net-q16-hdri-openmp-arm64 - 14.10.2;magick.net-q8-anycpu - 14.10.2;magick.net-q16-anycpu - 14.10.2;magick.net-q16-hdri-anycpu - 14.10.2;https://github.com/ImageMagick/ImageMagick.git - 7.1.2-13

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): HIGH

Do you need more information?

Contact Us