CVE-2026-42050: ImageMagick: Stack buffer overflow in XTileImage
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in the display tool and right-clicks a tile to invoke the Load / Update menu item. This vulnerability is fixed in 7.1.2-21 and 6.9.13-46.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42050?
CVE-2026-42050 has been rated as high severity due to the potential for exploitation through crafted MIFF files.
How do I fix CVE-2026-42050?
To fix CVE-2026-42050, update ImageMagick to version 7.1.2-21 or later, or 6.9.13-46 or later.
What versions of ImageMagick are affected by CVE-2026-42050?
Versions prior to 7.1.2-21 and 6.9.13-46 of ImageMagick are affected by CVE-2026-42050.
What type of files are involved in CVE-2026-42050?
CVE-2026-42050 involves malicious MIFF files that could trigger an overflow when opened in ImageMagick.
Can CVE-2026-42050 be exploited remotely?
Yes, CVE-2026-42050 can be exploited remotely if a user opens a crafted MIFF file.