Heap Buffer Overflow Vulnerability in ICC Color Management Library by iccDEV
CVE-2026-27692

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 February 2026

What is CVE-2026-27692?

The iccDEV library, utilized for ICC color management profiles, is susceptible to a heap buffer overflow. This occurs specifically in the CIccTagTextDescription::Release() function, where the strlen() function can read beyond allocated heap memory while parsing XML text description tags of ICC profiles. The flaw can lead to a crash, causing disruptions in applications relying on this library. No workarounds are available, but the vulnerability has been addressed in commit 29d088840b962a7cdd35993dfabc2cb35a049847.

Affected Version(s)

iccDEV <= 2.3.1.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.