Undefined Behavior Vulnerability in iccDEV Library
CVE-2026-24407

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 January 2026

What is CVE-2026-24407?

The iccDEV library, developed by the International Color Consortium, has an undefined behavior vulnerability in its function icSigCalcOp() when handling user-controllable input. This issue arises from unsafe incorporation of data into ICC profile structures, placing the integrity, availability, and execution flow of applications at risk. Successful exploitation of this vulnerability could lead to denial-of-service attacks, unauthorized manipulation of application data, and even arbitrary code execution. This security issue has been addressed in version 2.3.1.2.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.