4
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Description
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Basic Information
ID
CVE-2026-41254
Source
mitre
Published
Apr 18, 2026 at 06:43
Affected Product
Vendor
littlecms
Product
little cms color engine
Affected Versions
littlecms little cms color engine 0
CWE Classification
References
- github.com /mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0
- github.com /mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc
- www.openwall.com /lists/oss-security/2026/04/17/16
- github.com /mm2/Little-CMS/security/advisories/GHSA-4xp6-rcgg-m9qq
- abhinavagarwal07.github.io /posts/lcms2-cubesize-overflow/