Undefined Behavior in ICC Color Management Libraries from International Color Consortium
CVE-2026-34533

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34533?

The vulnerability arises in the ICC color management libraries provided by the International Color Consortium, specifically affecting versions prior to 2.3.1.6 of the iccDEV toolkit. A crafted ICC profile can cause undefined behavior in the CIccCalculatorFunc::ApplySequence() function due to the loading of invalid enum values for the icChannelFuncSignature. This anomaly has the potential to lead to type/enum value confusion during the processing of ICC profiles, which has been identified and corrected in the specified patched version. Users are encouraged to upgrade to the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.