iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write vulnerabilities in its CIccSparseMatrix::CIccSparseMatrix function. This issue is fixed in version 2.3.1.2.
References
Configurations
History
12 Jan 2026, 20:59
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Color
Color iccdev |
|
| References | () https://github.com/InternationalColorConsortium/iccDEV/commit/1ab7363f38a20089934d3410c88f714eea392bf5 - Patch | |
| References | () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-mg98-j5q2-674w - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* |
06 Jan 2026, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-06 04:15
Updated : 2026-01-12 20:59
NVD link : CVE-2026-21486
Mitre link : CVE-2026-21486
CVE.ORG link : CVE-2026-21486
JSON object : View
Products Affected
color
- iccdev
