PT-2026-29384 · Iccdev · Iccdev

Xsscx

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34535

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.6
Description iccDEV is a set of libraries and tools for working with ICC color management profiles. A crafted ICC profile can trigger a segmentation fault (SEGV) in the CIccTagArray::Cleanup() function, leading to a process crash when running iccRoundTrip on a malicious profile. The issue is observable under UBSan/ASan as misaligned member access and misaligned pointer loads followed by an invalid read.
Recommendations Update to version 2.3.1.6 or later.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-34535
GHSA-965Q-9PP6-6VW5

Affected Products

Iccdev