Reliance on undefined behavior in iccDEV - CVE-2026-34533
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to reliance on undefined behavior in CIccCalculatorFunc::ApplySequence() when processing a crafted ICC profile. A remote attacker can supply a crafted ICC profile with invalid enum values to cause a denial of service.
The issue is observable under UBSan as invalid values being loaded for icChannelFuncSignature.