Size_t Underflow Vulnerability in ICC Color Management Library by iccDEV
CVE-2026-50278
6.5MEDIUM
What is CVE-2026-50278?
A vulnerability exists in the iccDEV Color Management Library affecting versions earlier than 2.3.2.1. This issue arises from a size_t underflow in the CIccEmbedIO::Read8() function, which can occur when parsing ICC profiles that contain specific embedded-profile data. The vulnerability may allow an attacker to exploit the embedded-profile read defect, potentially leading to application instability or other unintended behaviors. Upgrading to version 2.3.2.1 patches this defect; however, there are currently no known workarounds available.
Affected Version(s)
iccDEV < 2.3.2.1
