← back
CVE-2026-56364lowCWE-401

ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 1.8epss 0.2%
exploitation probability
0.2%top 95% of all CVEs
observed exploitation
nono source reports it
ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files to exhaust memory and cause denial of service.
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N