ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
History

Fri, 15 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 13 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.
Title ImageMagick Undefined Behavior (function-type-mismatch) in CloneSplayTree
Weaknesses CWE-758
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-13T14:00:53.826Z

Updated: 2025-08-13T14:26:49.201Z

Reserved: 2025-08-07T18:27:23.306Z

Link: CVE-2025-55160

cve-icon Vulnrichment

Updated: 2025-08-13T14:26:40.562Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-13T14:15:33.177

Modified: 2025-08-15T19:25:21.890

Link: CVE-2025-55160

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-13T14:00:53Z

Links: CVE-2025-55160 - Bugzilla