CVE-2026-25584

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a stack-buffer-overflow vulnerability in CIccTagFloatNum<>::GetValues(). This is triggered when processing a malformed ICC profile. The vulnerability allows an out-of-bounds write on the stack, potentially leading to memory corruption, information disclosure, or code execution when processing specially crafted ICC files. This issue has been patched in version 2.3.1.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

18 Feb 2026, 18:37

Type Values Removed Values Added
References () https://github.com/InternationalColorConsortium/iccDEV/commit/c9cb108f58683bd87afca616dea3e4cdb884c23f - () https://github.com/InternationalColorConsortium/iccDEV/commit/c9cb108f58683bd87afca616dea3e4cdb884c23f - Patch
References () https://github.com/InternationalColorConsortium/iccDEV/issues/551 - () https://github.com/InternationalColorConsortium/iccDEV/issues/551 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/InternationalColorConsortium/iccDEV/pull/565 - () https://github.com/InternationalColorConsortium/iccDEV/pull/565 - Patch
References () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-xjr3-v3vr-5794 - () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-xjr3-v3vr-5794 - Vendor Advisory
Summary
  • (es) iccDEV proporciona un conjunto de librerías y herramientas que permiten la interacción, manipulación y aplicación de perfiles de gestión de color ICC. Antes de la versión 2.3.1.3, existe una vulnerabilidad de desbordamiento de búfer de pila (stack-buffer-overflow) en CIccTagFloatNum&lt;&gt;::GetValues(). Esto se activa al procesar un perfil ICC malformado. La vulnerabilidad permite una escritura fuera de límites en la pila, lo que podría conducir a corrupción de memoria, revelación de información o ejecución de código al procesar archivos ICC especialmente diseñados. Este problema ha sido parcheado en la versión 2.3.1.3.
CPE cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
First Time Color
Color iccdev

04 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 22:16

Updated : 2026-02-18 18:37


NVD link : CVE-2026-25584

Mitre link : CVE-2026-25584

CVE.ORG link : CVE-2026-25584


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write

CWE-788

Access of Memory Location After End of Buffer