<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T18:09:00.619081+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03385</id>
    <title>bdu:2026-03385</title>
    <updated>2026-10-04T18:09:00.840200+00:00</updated>
    <content>bdu:2026-03385</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-256945</id>
    <title>EUVD-2026-256945</title>
    <updated>2026-10-04T18:09:00.840239+00:00</updated>
    <content>EUVD-2026-256945</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-256945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62594</id>
    <title>fkie_cve-2025-62594</title>
    <updated>2026-10-04T18:09:00.840253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-62594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wpp4-vqfq-v4hp</id>
    <title>GHSA-wpp4-vqfq-v4hp — ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)</title>
    <updated>2026-10-04T18:09:00.840284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Magick.NET-Q16-x64, NuGet: Magick.NET-Q8-x64, NuGet: Magick.NET-Q16-HDRI-x64, NuGet: Magick.NET-Q8-OpenMP-x64, NuGet: Magick.NET-Q16-HDRI-OpenMP-x64, NuGet: Magick.NET-Q16-OpenMP-x64, NuGet: Magick.NET-Q8-arm64, NuGet: Magick.NET-Q16-arm64, NuGet: Magick.NET-Q16-OpenMP-arm64, NuGet: Magick.NET-Q8-OpenMP-arm64 and 2 more</p>
<p>## Summary</p>
<p>A single root cause in the CLAHE implementation — tile width/height becoming zero — produces two distinct but related unsafe behaviors.
Vulnerabilities exists in the `CLAHEImage()` function of ImageMagick’s `MagickCore/enhance.c`.</p>
<p>1. Unsigned integer underflow → out-of-bounds pointer arithmetic (OOB): when `tile_info.height == 0`, the expression `tile_info.height - 1` (unsigned) wraps to a very large value; using that value in pointer arithmetic yields a huge offset and OOB memory access (leading to memory corruption, SIGSEGV, or resource exhaustion).
2. **Division/modulus by zero**: where code performs `... / tile_info.width` or `... % tile_info.height` without re-checking for zero, causing immediate division-by-zero crashes under sanitizers or `abort` at runtime.</p>
<p>Both behaviors are triggered by the same invalid tile condition (e.g., CLI exact `-clahe 0x0!` or automatic tile derivation `dim &gt;&gt; 3 == 0` for very small images).</p>
<p>---</p>
<p>## Details</p>
<p>### **Unsigned underflow(can lea to OOB)**</p>
<p>- Location: `MagickCore/enhance.c`, around line 609
- Version tested: 7.1.2-8 (local ASan(undefined). /UBSan build)
- Vulnerable code
    
    enhance.c: 609
    
    ```c
    p += (ptrdiff_t) clahe_info-&gt;width * (tile.height - 1);
    ```
    
- Root Cause
    - If `tile.height == 0`, then `(tile.height - 1)` underflows to `UINT_MAX`.
    - Multiplication with `clahe_info-&gt;width` yields a huge value close to `SIZE_MAX`.
    - Adding this to `p` causes pointer arithmetic underf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wpp4-vqfq-v4hp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2587</id>
    <title>OESA-2025-2587 — ImageMagick security update</title>
    <updated>2026-10-04T18:09:00.840375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: ImageMagick</p>
<p>Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.

Security Fix(es):</p>
<p>ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.(CVE-2025-62594)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15685-1</id>
    <title>openSUSE-SU-2025:15685-1 — ImageMagick-7.1.2.8-1.1 on GA media</title>
    <updated>2026-10-04T18:09:00.840404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ImageMagick-7.1.2.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15685-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21211-1</id>
    <title>SUSE-SU-2025:21211-1 — Security update for ImageMagick</title>
    <updated>2026-10-04T18:09:00.840422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ImageMagick</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21211-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62594</id>
    <title>UBUNTU-CVE-2025-62594</title>
    <updated>2026-10-04T18:09:00.840438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: imagemagick, Ubuntu:26.04:LTS: imagemagick</p>
<p>ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62594"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2411</id>
    <title>WID-SEC-W-2025-2411 — ImageMagick: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T18:09:00.840459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2411"/>
  </entry>
</feed>
