Undefined Behavior and Null Pointer Dereference in iccDEV Libraries
CVE-2026-24409
7.1HIGH
What is CVE-2026-24409?
The iccDEV libraries, utilized for managing ICC color profiles, have a vulnerability that occurs due to unsafe incorporation of user-controllable input into ICC profile data. This vulnerability can lead to undefined behavior and null pointer dereference, resulting in potential disruptions such as denial of service (DoS) or malicious data manipulation. Attackers can exploit this flaw to bypass application logic or execute arbitrary code by carefully crafting inputs. The issue has been addressed in version 2.3.1.2.
Affected Version(s)
iccDEV < 2.3.1.2
