Buffer Overflow in iccDEV Color Management Library by International Color Consortium
CVE-2026-25634

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
6 February 2026

What is CVE-2026-25634?

A buffer overflow vulnerability exists in the iccDEV color management library before version 2.3.1.4. Specifically, this flaw arises from the overlapping of SrcPixel and DestPixel stack buffers within the CIccTagMultiProcessElement::Apply() function in IccTagMPE.cpp. This issue can potentially lead to unexpected behavior, including memory corruption. Users are advised to update to version 2.3.1.4 or later to mitigate the risks associated with this vulnerability.

Affected Version(s)

iccDEV < 2.3.1.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.