Undefined Behavior Vulnerability in ICC Color Management Library by International Color Consortium
CVE-2026-34549

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34549?

The ICC color management library, iccDEV, previously had a vulnerability that led to Undefined Behavior (UB) due to improper handling of input profiles. This condition, present prior to version 2.3.1.6, allowed for invalid left shift operations on icUInt32Number, potentially causing unpredictable behavior and system instability. The issue was adequately addressed in version 2.3.1.6, with patch notes available in the project's repository.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.