Undefined Behavior and Null Pointer Deference in ICC Color Management Library by iccDEV
CVE-2026-24410

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 January 2026

What is CVE-2026-24410?

The iccDEV ICC color management library, specifically in versions up to 2.3.1.1, has a flaw in the CIccProfileXml::ParseBasic() function that leads to undefined behavior and null pointer dereferencing. This vulnerability arises when user-controlled input is inadequately sanitized before being processed within ICC profile data or other structured binary formats. As a result, an attacker can exploit this flaw to induce denial-of-service (DoS) conditions, manipulate application data, bypass critical application logic, or potentially execute arbitrary code. Users are advised to upgrade to version 2.3.1.2 where this issue has been addressed.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.