PT-2026-6330 · Iccdev · Iccdev

Xsscx

·

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2026-25585

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.3
Description iccDEV is a set of libraries and tools for interacting with ICC color management profiles. A flaw exists in the color management module due to improper array bounds validation when processing ICC profiles. Specifically, a malformed ICC profile can trigger an out-of-bounds read at IccCmm.cpp:5793, potentially leading to memory disclosure or a segmentation fault.
Recommendations Update to version 2.3.1.3 or later.

Exploit

Fix

Out of bounds Read

Improper Validation of Array Index

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-25585
GHSA-PMQX-Q624-JG6W

Affected Products

Iccdev