Undefined Behavior and Null Pointer Dereference in iccDEV Libraries
CVE-2026-24409

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 January 2026

What is CVE-2026-24409?

The iccDEV libraries, utilized for managing ICC color profiles, have a vulnerability that occurs due to unsafe incorporation of user-controllable input into ICC profile data. This vulnerability can lead to undefined behavior and null pointer dereference, resulting in potential disruptions such as denial of service (DoS) or malicious data manipulation. Attackers can exploit this flaw to bypass application logic or execute arbitrary code by carefully crafting inputs. The issue has been addressed in version 2.3.1.2.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.