Stack Overflow Vulnerability in iccDEV Libraries Affecting ICC Color Management
CVE-2026-30980

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30980?

The iccDEV library, developed by the International Color Consortium, has a stack overflow vulnerability located in the CIccBasicStructFactory::CreateStruct() function. Versions prior to 2.3.1.5 are susceptible to this issue, which can lead to uncontrolled recursion and stack exhaustion, potentially causing the program to crash. Users are advised to upgrade to version 2.3.1.5 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.