CVE-2026-34550

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccProfLib/IccIO.cpp caused by an implicit conversion from a negative signed integer to size_t (unsigned), which changes the value. This issue has been patched in version 2.3.1.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

20 Apr 2026, 14:33

Type Values Removed Values Added
References () https://github.com/InternationalColorConsortium/iccDEV/issues/718 - () https://github.com/InternationalColorConsortium/iccDEV/issues/718 - Issue Tracking, Exploit
References () https://github.com/InternationalColorConsortium/iccDEV/pull/727 - () https://github.com/InternationalColorConsortium/iccDEV/pull/727 - Issue Tracking, Patch
References () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-rmxp-pxf4-p7wm - () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-rmxp-pxf4-p7wm - Patch, Vendor Advisory
CPE cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
First Time Color
Color iccdev
Summary
  • (es) iccDEV proporciona un conjunto de bibliotecas y herramientas para trabajar con perfiles de gestión de color ICC. Antes de la versión 2.3.1.6, existe una condición de Comportamiento Indefinido (UB) en IccProfLib/IccIO.cpp causada por una conversión implícita de un entero con signo negativo a size_t (sin signo), lo que cambia el valor. Este problema ha sido parcheado en la versión 2.3.1.6.

31 Mar 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 23:17

Updated : 2026-04-20 14:33


NVD link : CVE-2026-34550

Mitre link : CVE-2026-34550

CVE.ORG link : CVE-2026-34550


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-681

Incorrect Conversion between Numeric Types