PT-2026-36080 · Unknown · Little Cms

Zerojackyi

·

Published

2026-04-30

·

Updated

2026-06-05

·

CVE-2026-42798

CVSS v3.1

4.0

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Little CMS (lcms2) versions 2.16 through 2.18
Description An integer overflow exists in the ParseCube() function within the cmscgats.c file. An integer overflow occurs when a program attempts to store a numeric value that is too large for the allocated storage space, potentially leading to unexpected behavior.
Recommendations Update to version 2.19.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42798
ECHO-F978-7A1E-3DD3
OESA-2026-2325
OESA-2026-2326
OESA-2026-2327
SUSE-SU-2026:22070-1
USN-8250-1

Affected Products

Little Cms