CVE-2026-33905: ImageMagick has an Out-of-Bounds read via -sample operation
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33905?
CVE-2026-33905 has been classified as a moderate severity vulnerability due to its potential to cause an out-of-bounds read.
How do I fix CVE-2026-33905?
To fix CVE-2026-33905, upgrade your ImageMagick installation to version 7.1.2-19 or later, or version 6.9.13-44 or later.
What does CVE-2026-33905 affect?
CVE-2026-33905 specifically affects ImageMagick versions prior to 7.1.2-19 and 6.9.13-44 when using the -sample operation.
How does CVE-2026-33905 exploit the system?
CVE-2026-33905 exploits the system by allowing an attacker to trigger an out-of-bounds read, potentially accessing unauthorized memory.
Are there any known workarounds for CVE-2026-33905?
Currently, the recommended workaround for CVE-2026-33905 is to avoid using the -sample operation until the software has been updated.