PT-2026-33596 · Unknown+2 · Little Cms+2
Published
2026-04-18
·
Updated
2026-06-01
·
CVE-2026-41254
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Little CMS (lcms2) versions prior to 2.19
Description
An integer overflow occurs in the
CubeSize calculation within the cmslut.c file because the overflow check is executed after the multiplication operation.Recommendations
Update to a version newer than 2.18.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Little Cms
Ubuntu