Undefined Behavior in ICC Color Management Tools by iccDEV
CVE-2026-34552

6.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34552?

iccDEV, known for its libraries and tools for ICC color management profiles, is affected by an undefined behavior vulnerability in IccTagLut.cpp. This issue arises from incorrect member access through a null pointer of the CIccApplyCLUT type. Developers using versions prior to 2.3.1.6 should upgrade to the latest version to mitigate this issue and ensure the integrity of their color management processes.

Affected Version(s)

iccDEV < 2.3.1.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.