CVE-2026-21485

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (UB) and Out of Memory errors. This issue is fixed in version 2.3.1.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

14 Jan 2026, 18:45

Type Values Removed Values Added
First Time Color
Color iccdev
CPE cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
References () https://github.com/InternationalColorConsortium/iccDEV/commit/c136aac51d25cbb4d9db63f071edad4f088843df - () https://github.com/InternationalColorConsortium/iccDEV/commit/c136aac51d25cbb4d9db63f071edad4f088843df - Patch
References () https://github.com/InternationalColorConsortium/iccDEV/issues/340 - () https://github.com/InternationalColorConsortium/iccDEV/issues/340 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-chp2-4gv5-2432 - () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-chp2-4gv5-2432 - Vendor Advisory

06 Jan 2026, 19:16

Type Values Removed Values Added
References () https://github.com/InternationalColorConsortium/iccDEV/issues/340 - () https://github.com/InternationalColorConsortium/iccDEV/issues/340 -

06 Jan 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-06 04:15

Updated : 2026-01-14 18:45


NVD link : CVE-2026-21485

Mitre link : CVE-2026-21485

CVE.ORG link : CVE-2026-21485


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-20

Improper Input Validation

CWE-125

Out-of-bounds Read

CWE-190

Integer Overflow or Wraparound

CWE-400

Uncontrolled Resource Consumption

CWE-476

NULL Pointer Dereference

CWE-787

Out-of-bounds Write

CWE-1284

Improper Validation of Specified Quantity in Input