Heap-based buffer overflow in iccDEV - CVE-2026-34535
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in CIccTagArray::Cleanup() when parsing a crafted ICC profile. A remote attacker can supply a malicious profile to cause a denial of service.
The issue is observable as misaligned member access and invalid reads that crash the process when running iccRoundTrip on the crafted profile.