CVE 8.8 HIGH

iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()_CVE-2026-21485

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (UB) and Out of Memory errors. This issue is fixed in version 2.3.1.2.

AI Analysis

Undefined Behavior (UB) and Out of Memory errors in iccDEV versions 2.3.1.1 and below

Basic Information

ID CVE-2026-21485
Source GitHub_M
Published Jan 6, 2026 at 03:17

Affected Product

Vendor InternationalColorConsortium
Product iccDEV
Version < 2.3.1.2
Affected Versions InternationalColorConsortium iccDEV < 2.3.1.2

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor InternationalColorConsortium
Product iccDEV
Version 2.3.1.1 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.