CVE-2026-34555

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a stack-buffer-overflow (SBO) in CIccTagFixedNum<>::GetValues() and a related bug chain. The primary crash is an AddressSanitizer-reported WRITE of size 4 that overflows a 4-byte stack variable (rv) via the call chain CIccTagFixedNum::GetValues() -> CIccTagStruct::GetElemNumberValue(). This issue has been patched in version 2.3.1.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

20 Apr 2026, 14:38

Type Values Removed Values Added
Summary
  • (es) iccDEV proporciona un conjunto de bibliotecas y herramientas para trabajar con perfiles de gestión de color ICC. Antes de la versión 2.3.1.6, existe un desbordamiento de búfer de pila (SBO) en CIccTagFixedNum&lt;&gt;::GetValues() y una cadena de errores relacionada. El fallo principal es una ESCRITURA de tamaño 4 reportada por AddressSanitizer que desborda una variable de pila de 4 bytes (rv) a través de la cadena de llamadas CIccTagFixedNum::GetValues() -&gt; CIccTagStruct::GetElemNumberValue(). Este problema ha sido parcheado en la versión 2.3.1.6.
First Time Color
Color iccdev
CPE cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
References () https://github.com/InternationalColorConsortium/iccDEV/issues/696 - () https://github.com/InternationalColorConsortium/iccDEV/issues/696 - Issue Tracking, Exploit
References () https://github.com/InternationalColorConsortium/iccDEV/issues/697 - () https://github.com/InternationalColorConsortium/iccDEV/issues/697 - Issue Tracking, Exploit
References () https://github.com/InternationalColorConsortium/iccDEV/issues/698 - () https://github.com/InternationalColorConsortium/iccDEV/issues/698 - Issue Tracking, Exploit
References () https://github.com/InternationalColorConsortium/iccDEV/issues/703 - () https://github.com/InternationalColorConsortium/iccDEV/issues/703 - Issue Tracking, Exploit
References () https://github.com/InternationalColorConsortium/iccDEV/pull/739 - () https://github.com/InternationalColorConsortium/iccDEV/pull/739 - Issue Tracking, Patch
References () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-983c-rgh5-4982 - () https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-983c-rgh5-4982 - Patch, Vendor Advisory

01 Apr 2026, 14:16

Type Values Removed Values Added
References () https://github.com/InternationalColorConsortium/iccDEV/issues/696 - () https://github.com/InternationalColorConsortium/iccDEV/issues/696 -

31 Mar 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 23:17

Updated : 2026-04-20 14:38


NVD link : CVE-2026-34555

Mitre link : CVE-2026-34555

CVE.ORG link : CVE-2026-34555


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-121

Stack-based Buffer Overflow