Heap-Based Buffer Overflow in iccDEV Libraries Affecting Color Management Tools
CVE-2026-30985

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-30985?

The iccDEV libraries, utilized for working with ICC color management profiles, exhibit a vulnerability that allows a heap-based buffer overflow in the CIccMatrixMath::SetRange() function. This flaw can result in memory corruption or application crashes. Users are strongly encouraged to update to version 2.3.1.5, where this issue has been patched to enhance security and stability. For more information, visit the GitHub advisory.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.