Integer overflow in iccDEV - CVE-2026-27691
Published: April 30, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to signed integer overflow in parse3DTable() in iccFromCube.cpp when processing crafted or large cube inputs. A remote attacker can supply a specially crafted cube input to cause a denial of service.
The issue may also result in incorrect ICC profile generation.