Magick fails to check for circular references between two MSLs, leading to a stack overflow.
After reading a.msl using magick, the following is displayed:
MSLStartElement -> ReadImage -> ReadMSLImage -> ProcessMSLScript -> xmlParseChunk -> xmlParseTryOrFinish -> MSLStartElement
AddressSanitizer:DEADLYSIGNAL
=================================================================
==114345==ERROR: AddressSanitizer: UNKNOWN SIGNAL on unknown address 0x000000000000 (pc 0x72509fc7d804 bp 0x7ffd6598b390 sp 0x7ffd6598ab20 T0)
#0 0x72509fc7d804 in strlen ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc:388
[...]
{
"sources": [
{
"modified": "2026-06-17T10:25:31.070Z",
"database_specific": {
"status": "Analyzed"
},
"id": "CVE-2026-25971",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25971",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-25971",
"imported": "2026-07-30T14:08:45.358Z",
"published": "2026-02-24T02:16:02.130Z"
},
{
"modified": "2026-03-12T14:02:06Z",
"published": "2026-03-12T14:02:04Z",
"id": "GHSA-8mpr-6xr2-chhc",
"url": "https://api.github.com/advisories/GHSA-8mpr-6xr2-chhc",
"imported": "2026-07-30T14:10:13.852Z",
"html_url": "https://github.com/advisories/GHSA-8mpr-6xr2-chhc"
},
{
"modified": "2026-06-23T15:49:17Z",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7427",
"id": "EUVD-2026-7427",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-7427",
"imported": "2026-07-30T14:08:52.930Z",
"published": "2026-02-24T01:39:21Z"
}
],
"license": "CC-BY-4.0"
}