Stack-based buffer overflow in iccDEV - CVE-2026-34542
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in CIccCalculatorFunc::Apply() when processing a crafted ICC profile via iccApplyNamedCmm. A remote attacker can supply a specially crafted ICC profile to cause a denial of service.
The issue is reachable through the MPE calculator and curve set initialization path.