Heap Buffer Overflow in iccDEV Library for ICC Color Management Profiles
CVE-2026-25582

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25582?

The iccDEV library, designed for managing ICC color profiles, is susceptible to a heap buffer overflow vulnerability in its CIccIO::WriteUInt16Float() function. This flaw occurs when processing malformed XML data into ICC profiles using the iccFromXml tool. Exploiting this vulnerability could potentially lead to unauthorized memory access. To protect against this issue, users should upgrade to version 2.3.1.3 or later, where the vulnerability has been addressed.

Affected Version(s)

iccDEV < 2.3.1.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.