{"id":"GHSA-8g9f-ccmr-vfvg","title":"Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder","summary":"Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder","severity":"medium","cvss":3.7,"cwe":["CWE-416"],"vendor":"Magick","product":"Magick.NET-Q16-AnyCPU","ecosystem":"nuget","affected":["Magick.NET-Q16-AnyCPU < 14.10.3"],"patched":["Magick.NET-Q16-AnyCPU 14.10.3"],"published":"2026-06-23","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:03:44Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-8g9f-ccmr-vfvg","references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2gq3-ww97-wfjm"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56376"},{"url":"https://www.vulncheck.com/advisories/imagemagick-heap-use-after-free-in-meta-coder"},{"url":"https://github.com/advisories/GHSA-8g9f-ccmr-vfvg"}],"tags":["ghsa","nuget"],"ingestedAt":"2026-09-24T20:51:40.263Z","slug":"GHSA-8g9f-ccmr-vfvg","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2gq3-ww97-wfjm. This link is maintained to preserve external references.\n\n### Original Description\nImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.\n\n## Affected packages\n\n- `Magick.NET-Q16-AnyCPU < 14.10.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `Magick.NET-Q16-AnyCPU 14.10.3`","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}