Stack Overflow Vulnerability in iccDEV Color Management Library
CVE-2026-34536
6.2MEDIUM
What is CVE-2026-34536?
The iccDEV library, utilized for handling ICC color management profiles, contains a vulnerability that can be exploited by a specially crafted ICC profile. This vulnerability leads to a stack overflow, particularly when the function SIccCalcOp::ArgsUsed() processes an incorrect profile in the iccApplyProfiles function. The flaw is detectable using AddressSanitizer and manifests as a stack overflow during checks for argument usage, potentially causing system crashes. This issue has been resolved in version 2.3.1.6 of the software.
Affected Version(s)
iccDEV < 2.3.1.6
