Return of Stack Variable Address in iccDEV - CVE-2026-34553

 

Return of Stack Variable Address in iccDEV - CVE-2026-34553

Published: May 5, 2026


Vulnerability identifier: #VU129827
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34553
CWE-ID: CWE-562
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify CLUT output.

The vulnerability exists due to return of stack variable address in CIccCLUT::DumpLut() and output produced by CIccMBB::Describe() when dumping CLUT data. A remote attacker can process a crafted ICC profile to modify CLUT output.

The issue is associated with dangling references to stack arrays through temporary buffer usage during CLUT dumping.


Affected software

iccDEV

How to mitigate CVE-2026-34553

Install security update from vendor's website.

iccDEV - update to 2.3.1.6

External References

Related Security Bulletins