Heap Out-of-Bounds Write in GraphicsMagick Photo CD Decoder
CVE-2026-77118
What is CVE-2026-77118?
A vulnerability exists in the Photo CD (PCD) decoder of GraphicsMagick where a heap out-of-bounds write can occur in the DecodeImage() function. This results from the Huffman delta loop advancing the output pointer without adequately checking its position, allowing it to write beyond the allocated memory for luma/chroma plane buffers. If a specially crafted PCD file is processed, it can initiate a write operation beyond the intended memory limits, corrupting the heap memory and potentially leading to application crashes or other unpredictable behaviors. Users are advised to upgrade to GraphicsMagick version 1.3.48 or later to mitigate this issue.
Affected Version(s)
graphicsmagick 0 < 1.4+really1.3.48-1
GraphicsMagick 0 < 1.3.48
GraphicsMagick Linux 1.0.0 < 1.3.48
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
