Uncontrolled Recursion in iccDEV - CVE-2026-34536
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in SIccCalcOp::ArgsUsed() when processing a crafted ICC profile. A remote attacker can supply a malicious profile to cause a denial of service.
The issue is triggered when iccApplyProfiles processes the crafted profile.