Heap-based buffer overflow in iccDEV - CVE-2026-34534
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in CIccMpeSpectralMatrix::Describe() when parsing a crafted ICC profile. A remote attacker can supply a specially crafted ICC profile to cause a denial of service.
The issue is observable as an out-of-bounds heap read when running iccDumpProfile on a malicious profile.