Skip to main content
Vulnerability Database/CVE-2026-93588

CVE-2026-93588: ImageMagick PNM Coder DOS Vulnerability

CVE-2026-93588 is a NULL pointer dereference flaw in ImageMagick's PNM coder that causes application crashes when processing crafted images. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-93588 Overview

CVE-2026-93588 is a NULL pointer dereference vulnerability in ImageMagick's Portable Anymap (PNM) coder. The flaw affects ImageMagick versions before 7.1.2-31 and before 6.9.13-56. When the PNM coder reaches a memory or resource limit at a specific point during image processing, the failed allocation is not checked before use. Subsequent dereference of the NULL pointer causes the application to crash. Attackers can trigger the condition by supplying a specially crafted or sufficiently large PNM image, resulting in denial of service against any service that processes untrusted PNM input through ImageMagick.

Critical Impact

Processing an attacker-supplied PNM image can crash ImageMagick, producing a denial-of-service condition in image processing pipelines, web upload handlers, and thumbnail services.

Affected Products

  • ImageMagick versions prior to 7.1.2-31 (7.x branch)
  • ImageMagick versions prior to 6.9.13-56 (6.x legacy branch)
  • Applications and services embedding vulnerable ImageMagick builds for PNM processing

Discovery Timeline

  • 2026-09-18 - CVE-2026-93588 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-93588

Vulnerability Analysis

The vulnerability is classified as a NULL pointer dereference [CWE-476] in the PNM decoder. ImageMagick enforces configurable resource limits covering memory, map, disk, area, and pixel cache size. When the PNM coder allocates buffers during decoding, an allocation may fail because a resource limit has been reached. The coder path does not validate the returned pointer before dereferencing it, causing an immediate crash. Because PNM is a permissive, size-driven format, attackers can craft small headers that declare large dimensions, forcing allocations that exceed configured limits. The result is a reliable, low-complexity crash of the host process consuming the image.

Root Cause

The root cause is missing return-value validation on a memory allocation call inside the PNM read path. ImageMagick's resource governor rejects allocations exceeding limits by returning a NULL pointer rather than aborting. The PNM coder proceeds to use that pointer as if the allocation succeeded, dereferencing it during pixel or scanline population.

Attack Vector

Exploitation requires an attacker to deliver a PNM (.pnm, .pbm, .pgm, or .ppm) image to a target that decodes it with a vulnerable ImageMagick build. Common exposure points include web application file uploads, document conversion services, mail scanners, and container image build pipelines that rely on convert, magick, or the MagickWand and MagickCore APIs. No authentication or user interaction beyond normal file submission is required for services that automatically process uploads. The impact is limited to availability; the vulnerability does not disclose data or enable code execution. Technical details are documented in the GitHub Security Advisory GHSA-92rw-c5mw-27v4 and the VulnCheck ImageMagick Advisory.

// No verified proof-of-concept code is published for CVE-2026-93588.
// Refer to the GitHub Security Advisory GHSA-92rw-c5mw-27v4 for technical details.

Detection Methods for CVE-2026-93588

Indicators of Compromise

  • Repeated segmentation faults or SIGSEGV crashes in processes invoking magick, convert, or identify against PNM inputs.
  • Core dumps whose faulting frame resides in the PNM read path (ReadPNMImage and related routines).
  • Web server or worker logs showing 5xx responses correlated with PNM upload requests.
  • Sudden restarts of image conversion workers or containers after processing user-supplied images.

Detection Strategies

  • Inventory installed ImageMagick versions across servers and containers, flagging any build below 7.1.2-31 or 6.9.13-56.
  • Monitor process exit codes and crash telemetry from any service that accepts image uploads or performs automated conversion.
  • Inspect uploaded files for PNM magic bytes (P1 through P6) combined with unusually large declared dimensions in the header.

Monitoring Recommendations

  • Alert on abnormal restart rates for image processing daemons and conversion queue workers.
  • Correlate crash events with the source IP and account submitting the triggering file to identify targeted denial-of-service attempts.
  • Track resource-limit rejections logged by ImageMagick's policy engine as a leading indicator of probing activity.

How to Mitigate CVE-2026-93588

Immediate Actions Required

  • Upgrade ImageMagick to 7.1.2-31 or later on the 7.x branch, or 6.9.13-56 or later on the 6.x branch.
  • Rebuild and redeploy container images and application bundles that statically link or vendor ImageMagick.
  • Restrict accepted image formats at the application layer, rejecting PNM variants where they are not required.
  • Isolate image processing in sandboxed workers with automatic restart to limit the impact of crashes.

Patch Information

The upstream project addressed the missing allocation check in the PNM coder in releases 7.1.2-31 and 6.9.13-56. Fix details are published in the GitHub Security Advisory GHSA-92rw-c5mw-27v4. Downstream distributions typically ship the fix as a backported patch; verify the installed package version against your distribution's security tracker.

Workarounds

  • Tighten policy.xml to disable the PNM coder where the format is not needed, using a <policy domain="coder" rights="none" pattern="PNM" /> entry.
  • Lower ImageMagick resource limits (memory, map, area, width, height) to reject oversized images before they reach the vulnerable code path.
  • Validate image dimensions and file size at the application tier before invoking ImageMagick.
  • Run conversion workloads under a process supervisor that restarts crashed workers and rate-limits repeated failures from the same source.
bash
# /etc/ImageMagick-7/policy.xml example
# Disable PNM decoding and cap resource usage
<policymap>
  <policy domain="coder" rights="none" pattern="PNM" />
  <policy domain="coder" rights="none" pattern="PBM" />
  <policy domain="coder" rights="none" pattern="PGM" />
  <policy domain="coder" rights="none" pattern="PPM" />
  <policy domain="resource" name="memory" value="256MiB" />
  <policy domain="resource" name="map" value="512MiB" />
  <policy domain="resource" name="width" value="16KP" />
  <policy domain="resource" name="height" value="16KP" />
</policymap>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.