Medium severity6.1NVD Advisory· Published Jan 7, 2026· Updated Jun 17, 2026
CVE-2026-21503
CVE-2026-21503
Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to a null pointer passed to memcpy() in CIccTagSparseMatrixArray. This issue has been patched in version 2.3.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.3.1.2+ 1 more
- (no CPE)range: <2.3.1.2
- (no CPE)range: < 2.3.1.2
Patches
Vulnerability mechanics
References
4- github.com/InternationalColorConsortium/iccDEV/commit/55259a6395c4f6124b5d0e38469c77412926bd3dnvdPatch
- github.com/InternationalColorConsortium/iccDEV/issues/367nvdExploitIssue Tracking
- github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-h554-qrfh-53gxnvdThird Party Advisory
- github.com/InternationalColorConsortium/iccDEV/pull/417nvdIssue Tracking
News mentions
0No linked articles in our index yet.