PT-2026-2185 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2026-22255

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools for interacting with International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 contain a heap-buffer-overflow issue in the CIccCLUT::Init() function located in IccProfLib/IccTagLut.cpp. This affects users of the iccDEV library when processing ICC color profiles.
Recommendations Versions prior to 2.3.1.2 should be updated to version 2.3.1.2 or later.

Exploit

Fix

Unchecked Return Value

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-22255
GHSA-QV2W-MQ3G-73GV

Affected Products

Iccdev