Null Pointer Dereference in ICC Color Management Profiles Library by iccDEV
CVE-2026-31792
7.8HIGH
What is CVE-2026-31792?
The iccDEV library, which provides essential tools for managing ICC color profiles, contains a vulnerability that allows for a null pointer dereference in the CIccTagXmlStruct::ParseTag() function. This flaw can result in a segmentation fault, leading to potential denial of service. Users are strongly advised to update to version 2.3.1.5, where this issue has been resolved. For more details, check the advisory on GitHub.
Affected Version(s)
iccDEV < 2.3.1.5
