ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
{
"cwe_ids": [
"CWE-400"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24485.json"
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "14.10.3"
}
]
}[
{
"digest": {
"length": 4282.0,
"function_hash": "282411404119602468345796350123409734484"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2026-24485-7dd5b857",
"target": {
"function": "DecodeImage",
"file": "coders/pcd.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/332c1566acc2de77857032d3c2504ead6210ff50"
},
{
"digest": {
"length": 9087.0,
"function_hash": "45055149258289649364754692823637859386"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2026-24485-bb11c7a9",
"target": {
"function": "ReadPCDImage",
"file": "coders/pcd.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/332c1566acc2de77857032d3c2504ead6210ff50"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"189898845361711089250117854452224324472",
"276933276159496308319453859954213477527",
"154434319782377540866425960738998685465",
"42405739800522106034459202191436754485",
"49412389962094737324619921131711185300",
"69630588205881666527495182715548497883",
"334203531416451128418735503560260024692",
"32209268759564236459373131693252215838",
"12067946554662062768104976636464814331",
"309148363128360010761793873793280910847",
"5335378045637428308775087444610948265",
"338914879616607569426407281379890412440",
"58235052189917025146184079473117609756",
"288694917003553285227683949138963286775",
"16211166298936594268177855713583645406",
"173637353801206326318173925221777233991",
"57972957212358207272570724556863673507",
"17345056290600681730887986434780537634",
"91958398106729212340254714043893931607",
"218015432387540844795329772295765943102",
"142106196595950630205775646604878982083",
"324074424425842686932341135538583298946",
"245382104547498965774416545606965059881",
"172578144198658293637632690482330157366",
"281409708842400080089677150774544880185",
"51390384558089592737831568056610899996",
"206833111905010763713801759029832271658",
"76671317999426919838351688436638198622",
"251292736531704210133753480109931212316",
"141141779714519138132283535252974999799",
"52525227773542723027868550722040928942",
"73148889406812796652075682511318172691",
"218864785513263653472656178010981681204",
"112174718056450567847818377974250517673",
"200398144316523249191797140955033157473",
"162171921630641627396559233715719438959",
"46564337884240946625958183791225792096",
"265765057831181762836644815614051461010",
"46725602913634239815950832978431086862",
"25560455901640446718504136629307261284",
"156156597529486235867965020878116483284",
"37181404633333681870193566482524121050",
"314093298092115570860145454733944969421",
"47672868041140367472745155467178894365",
"234676471997219113684245132940665829664",
"245971233728279377537430300636687827758",
"225925201680363922119358689930247427452",
"207180961424830075115447815296143754210",
"222259773586783239049117195918453625145",
"50467771221697342604308981303040818033",
"87712616831320460902333362597067033438",
"138478201611570191481512487431067969054",
"191228113623807542229141915038172796105",
"5539954649547806528896777300683059202",
"176238546269875294581123026478989383612",
"174527551308244827393335455516139150554",
"217766823411941572120018314832456934920",
"232670305282617304636381354072176991144",
"235388829543563375353377482248875762137",
"278452922448299644567018879236300022653",
"77732154398813679238995290181620063143",
"184823051526077376450315086036969158884"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2026-24485-d05db23a",
"target": {
"file": "coders/pcd.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/332c1566acc2de77857032d3c2504ead6210ff50"
}
]
[
{
"events": [
{
"introduced": "7.0.0-0"
},
{
"fixed": "7.1.2-15"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24485.json"