Segmentation Fault Vulnerability in iccDEV Color Management Tools
CVE-2026-34535
6.2MEDIUM
What is CVE-2026-34535?
The iccDEV color management libraries are vulnerable to a segmentation fault caused by a maliciously crafted ICC profile. This vulnerability manifests when the CIccTagArray::Cleanup() function encounters misaligned member accesses and pointer loads. Under certain conditions, specifically with the use of UBSan/ASan, these misalignments can lead to an invalid read and eventual crash of the process when executing the iccRoundTrip function on a compromised profile. Users are advised to upgrade to version 2.3.1.6 or later, where this issue has been addressed.
Affected Version(s)
iccDEV < 2.3.1.6
