Reliance on undefined behavior in iccDEV - CVE-2026-34547
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reliance on undefined behavior in IccUtil.cpp when parsing a crafted ICC profile with iccDumpProfile. A remote attacker can supply a specially crafted ICC profile to cause a denial of service.
The issue is triggered while running iccDumpProfile on malformed profile data.