Heap Buffer Overflow in iccDEV Library for ICC Color Management Profiles
CVE-2026-25582
7.8HIGH
What is CVE-2026-25582?
The iccDEV library, designed for managing ICC color profiles, is susceptible to a heap buffer overflow vulnerability in its CIccIO::WriteUInt16Float() function. This flaw occurs when processing malformed XML data into ICC profiles using the iccFromXml tool. Exploiting this vulnerability could potentially lead to unauthorized memory access. To protect against this issue, users should upgrade to version 2.3.1.3 or later, where the vulnerability has been addressed.
Affected Version(s)
iccDEV < 2.3.1.3
