CVE-2026-27692

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:27

Type Values Removed Values Added
Summary
  • (es) iccDEV proporciona un conjunto de librerías y herramientas para trabajar con perfiles ICC de gestión de color. En versiones hasta la 2.3.1.4 inclusive, se produce una lectura de desbordamiento de búfer de montón durante CIccTagTextDescription::Release() cuando strlen() lee más allá de un búfer de montón mientras analiza etiquetas de descripción de texto XML de perfiles ICC, causando un fallo. El commit 29d088840b962a7cdd35993dfabc2cb35a049847 corrige el problema. No se conocen soluciones alternativas disponibles.

26 Feb 2026, 15:43

Type Values Removed Values Added
CPE cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
First Time Color
Color iccdev
References () https://github.com/InternationalColorConsortium/iccDEV/commit/29d088840b962a7cdd35993dfabc2cb35a049847 - () https://github.com/InternationalColorConsortium/iccDEV/commit/29d088840b962a7cdd35993dfabc2cb35a049847 - Patch
References () https://github.com/InternationalColorConsortium/iccDEV/issues/609 - () https://github.com/InternationalColorConsortium/iccDEV/issues/609 - Exploit, Issue Tracking
References () https://github.com/InternationalColorConsortium/iccDEV/pull/610 - () https://github.com/InternationalColorConsortium/iccDEV/pull/610 - Issue Tracking, Patch
References () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-3869-prw8-gjqr - () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-3869-prw8-gjqr - Vendor Advisory

25 Feb 2026, 15:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 15:20

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27692

Mitre link : CVE-2026-27692

CVE.ORG link : CVE-2026-27692


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-125

Out-of-bounds Read

CWE-170

Improper Null Termination

CWE-787

Out-of-bounds Write