Stack Buffer Overflow in iccDEV Libraries prior to Version 2.3.1.5
CVE-2026-31795

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-31795?

The iccDEV library, utilized for managing ICC color profiles, contains a vulnerability that can lead to a stack buffer overflow in the function CIccXform3DLut::Apply(). This flaw can result in corrupted stack memory or application crashes. Users are encouraged to update to version 2.3.1.5, where this issue has been addressed, to maintain the integrity and stability of the application.

Affected Version(s)

iccDEV < 2.3.1.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.