CVE-2026-77118
EUVD-2026-6334520.08.2026, 13:19
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input. A crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| graphicsmagick | graphicsmagick | 1.0.0 ≤ 𝑥 < 1.3.48 | CNA |
| graphicsmagick | graphicsmagick | 𝑥 < 1.3.48 | CNA |
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| GraphicsMagick |
| ||
| GraphicsMagick-c++ |
| ||
| GraphicsMagick-c++-debuginfo |
| ||
| GraphicsMagick-c++-devel |
| ||
| GraphicsMagick-debuginfo |
| ||
| GraphicsMagick-debugsource |
| ||
| GraphicsMagick-devel |
| ||
| GraphicsMagick-doc |
| ||
| GraphicsMagick-perl |
| ||
| GraphicsMagick-perl-debuginfo |
|
Common Weakness Enumeration