Home

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusion allowed malformed ICC profiles to trigger undefined behavior when loading invalid icImageEncodingType values causing denial of service. This issue has been patched in version 2.3.1.2.

PUBLISHED Reserved 2026-02-02 | Published 2026-02-03 | Updated 2026-02-04 | Assigner GitHub_M




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Problem types

CWE-704: Incorrect Type Conversion or Cast

CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')

Product status

< 2.3.1.2
affected

References

github.com/InternationalColorConsortium/iccDEV/issues/539 exploit

github.com/...iccDEV/security/advisories/GHSA-pf84-4c7q-x764

github.com/InternationalColorConsortium/iccDEV/issues/539

github.com/InternationalColorConsortium/iccDEV/pull/547

github.com/...ommit/353e6517a31cb6ac9fdd44ac0103bc2fadb25175

cve.org (CVE-2026-25503)

nvd.nist.gov (CVE-2026-25503)

Download JSON