Unrated severityNVD Advisory· Published Jan 13, 2026· Updated Jan 13, 2026
iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
CVE-2026-22861
Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. The vulnerability is fixed in 2.3.1.2.
Affected products
2- InternationalColorConsortium/iccDEVv5Range: < 2.3.1.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/InternationalColorConsortium/iccDEV/commit/fa9a364c01fc2e59eb2291e1f9b1c1359b7d5329mitrex_refsource_MISC
- github.com/InternationalColorConsortium/iccDEV/pull/475mitrex_refsource_MISC
- github.com/InternationalColorConsortium/iccDEV/pull/476mitrex_refsource_MISC
- github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-vr49-3vf8-7j5hmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.