PT-2026-6330 · Iccdev · Iccdev

·

CVE-2026-25585

·

Published

2026-02-04

·

Updated

2026-02-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.3
Description iccDEV is a set of libraries and tools for interacting with ICC color management profiles. A flaw exists in the color management module due to improper array bounds validation when processing ICC profiles. Specifically, a malformed ICC profile can trigger an out-of-bounds read at IccCmm.cpp:5793, potentially leading to memory disclosure or a segmentation fault.
Recommendations Update to version 2.3.1.3 or later.

Exploit

Fix

Out of bounds Read

Improper Validation of Array Index

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25585
GHSA-PMQX-Q624-JG6W

Affected Products

Iccdev