NULL pointer dereference in iccDEV - CVE-2026-34552
Published: May 5, 2026
iccDEV
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in IccTagLut.cpp when processing a malformed ICC profile through the LUT application path. A remote attacker can supply a specially crafted ICC profile to cause a denial of service.
The issue was reported at IccTagLut.cpp:3181:31 while running iccRoundTrip on a provided ICC profile.