PT-2026-29393 · Iccdev · Iccdev

Xsscx

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34548

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.6
Description iccDEV is a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.1.6 contain an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) due to an implicit conversion from a negative signed integer to icUInt32Number (unsigned 32-bit), which alters the value.
Recommendations Versions prior to 2.3.1.6 should be updated to version 2.3.1.6 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-34548
GHSA-PRWP-9GV6-CCXV

Affected Products

Iccdev