NULL pointer dereference in iccDEV - CVE-2026-34541
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions() when processing a malformed ICC profile with iccApplyNamedCmm using the -PCC option. A remote attacker can supply a specially crafted ICC profile to cause a denial of service.
The issue is reported in IccProfLib/IccPcc.cpp.