Home

Description

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

PUBLISHED Reserved 2026-04-30 | Published 2026-04-30 | Updated 2026-04-30 | Assigner mitre




MEDIUM: 4.0CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Problem types

CWE-190 Integer Overflow or Wraparound

Product status

Default status
unaffected

2.16 (custom) before 2.19
affected

References

github.com/...ommit/6a686019825a89b715d16671f18d049523354176

github.com/mm2/Little-CMS/compare/lcms2.18...lcms2.19

www.openwall.com/lists/oss-security/2026/04/30/8

cve.org (CVE-2026-42798)

nvd.nist.gov (CVE-2026-42798)

Download JSON