Type Confusion Vulnerability in iccDEV Color Management Libraries
CVE-2026-25503

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2026-25503?

The iccDEV libraries, used for managing ICC color management profiles, exhibit a type confusion vulnerability that allows for undefined behavior when processing malformed ICC profiles prior to version 2.3.1.2. This vulnerability could result in denial of service when invalid icImageEncodingType values are loaded. A patch addressing this issue has been implemented in version 2.3.1.2 to enhance the stability and security of the product.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.