🔐 CVE Alert

CVE-2025-65955

MEDIUM 4.9

ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

CWE CWE-415 CWE-416
Vendor imagemagick
Product imagemagick
Published Dec 2, 2025
Last Updated Jun 23, 2026
Stay Ahead of the Next One

Get instant alerts for imagemagick imagemagick

Be the first to know when new medium vulnerabilities affecting imagemagick imagemagick are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

ImageMagick / ImageMagick
>= 7.0.1-0, < 7.1.2-9 < 6.9.13-34

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q3hc-j9x5-mp9m github.com: https://github.com/ImageMagick/ImageMagick/commit/6409f34d637a34a1c643632aa849371ec8b3b5a8 github.com: https://github.com/ImageMagick/ImageMagick/commit/6f81eb15f822ad86e8255be75efad6f9762c32f8