Heap Buffer Overflow Vulnerability in ICC Color Management Library by iccDEV
CVE-2026-27692
7.1HIGH
What is CVE-2026-27692?
The iccDEV library, utilized for ICC color management profiles, is susceptible to a heap buffer overflow. This occurs specifically in the CIccTagTextDescription::Release() function, where the strlen() function can read beyond allocated heap memory while parsing XML text description tags of ICC profiles. The flaw can lead to a crash, causing disruptions in applications relying on this library. No workarounds are available, but the vulnerability has been addressed in commit 29d088840b962a7cdd35993dfabc2cb35a049847.
Affected Version(s)
iccDEV <= 2.3.1.4
