Null Pointer Dereference in ICC Color Management Profiles Library by iccDEV
CVE-2026-31792

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-31792?

The iccDEV library, which provides essential tools for managing ICC color profiles, contains a vulnerability that allows for a null pointer dereference in the CIccTagXmlStruct::ParseTag() function. This flaw can result in a segmentation fault, leading to potential denial of service. Users are strongly advised to update to version 2.3.1.5, where this issue has been resolved. For more details, check the advisory on GitHub.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.