ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initialized. This will result in a release of an invalid pointer inside DestroyBilateralTLS when the memory allocation fails. Version 7.1.2-13 contains a patch for the issue.
{
"cwe_ids": [
"CWE-763"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22770.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.1.2-13"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T16:24:51Z"
[
{
"id": "CVE-2026-22770-216278a9",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 532.0,
"function_hash": "117096807407238575577803741494964350256"
},
"source": "https://github.com/imagemagick/imagemagick/commit/3e0330721020e0c5bb52e4b77c347527dd71658e",
"target": {
"function": "AcquireBilateralTLS",
"file": "MagickCore/effect.c"
}
},
{
"id": "CVE-2026-22770-5a5e550e",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"210036853431467168827134391927468981962",
"38503099212936631525463073855120693884",
"121326523783367491537186400347407450536",
"227747708769178666577072343097034808406",
"33662205002685565724488427716982582768",
"320218704644340354230405390479622511230",
"58600378943697118229062584443865178044",
"158227362026220803673734451581788011231",
"313500641142571396998524873235202508446",
"245402331106841280488585519531539483832",
"62495244044158724884988524610232874476",
"213920262725936694212081375670868561642"
]
},
"source": "https://github.com/imagemagick/imagemagick/commit/3e0330721020e0c5bb52e4b77c347527dd71658e",
"target": {
"file": "MagickCore/effect.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22770.json"