PT-2026-29385 · Iccdev · Iccdev

Xsscx

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34536

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.6
Description iccDEV provides libraries and tools for working with ICC color management profiles. A manipulated ICC profile can trigger a stack overflow in SIccCalcOp::ArgsUsed(). The issue occurs when iccApplyProfiles processes a malicious profile, specifically during argument usage calculation for underflow/overflow checks. This issue was addressed in version 2.3.1.6.
Recommendations Versions prior to 2.3.1.6 should be updated to version 2.3.1.6 or later.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2026-34536
GHSA-CR68-XP9X-8597

Affected Products

Iccdev