Vulnerability Details CVE-2026-34554
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) in CIccApplyCmmSearch::costFunc() can be triggered via malformed JSON configuration input to the iccApplySearch tool. AddressSanitizer reports an out-of-bounds READ of size 8 originating from CIccApplyCmmSearch::costFunc(CIccSearchVec&) at IccProfLib/IccCmmSearch.cpp:112:5. This issue has been patched in version 2.3.1.6.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.3%
CVSS Severity
CVSS v3 Score 6.2
Products affected by CVE-2026-34554
-
cpe:2.3:a:color:iccdev:2.2.50
-
cpe:2.3:a:color:iccdev:2.2.6
-
cpe:2.3:a:color:iccdev:2.3.1
-
cpe:2.3:a:color:iccdev:2.3.1.1
-
cpe:2.3:a:color:iccdev:2.3.1.2
-
cpe:2.3:a:color:iccdev:2.3.1.3
-
cpe:2.3:a:color:iccdev:2.3.1.4