NULL pointer dereference in iccDEV - CVE-2026-34551
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in CIccTagLut16::Write() when processing a crafted ICC profile during iccTiffDump extraction and profile serialization. A remote attacker can supply a crafted ICC profile to cause a denial of service.
The crash is reported as a reference binding to a null pointer originating from CIccTagCurve::operator[].