Heap-based buffer overflow in iccDEV - CVE-2026-34535

 

Heap-based buffer overflow in iccDEV - CVE-2026-34535

Published: May 5, 2026


Vulnerability identifier: #VU129821
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34535
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to heap-based buffer overflow in CIccTagArray::Cleanup() when parsing a crafted ICC profile. A remote attacker can supply a malicious profile to cause a denial of service.

The issue is observable as misaligned member access and invalid reads that crash the process when running iccRoundTrip on the crafted profile.


Affected software

iccDEV

How to mitigate CVE-2026-34535

Install security update from vendor's website.

iccDEV - update to 2.3.1.6

External References

Related Security Bulletins