ID:12319 - Exploit for Memory leak in ImageMagick
Published: January 20, 2026
Vulnerability identifier: #VU121672
Vulnerability risk: Low
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Local access
Vulnerable software:
ImageMagick
ImageMagick
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak in the "LoadOpenCLDeviceBenchmark()" function in MagickCore/opencl.c. A local administrator can force the application to leak memory and perform denial of service attack.
Remediation
Install updates from vendor's website.