Heap-based buffer overflow in iccDEV - CVE-2026-34540
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in icMemDump() when dumping malformed tag contents from a crafted ICC profile. A remote attacker can supply a crafted ICC profile to cause a denial of service.
The issue is reachable via CIccTagUnknown::Describe().