CVE-2026-21486: Use After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEV
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below contain Use After Free, Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write vulnerabilities in its CIccSparseMatrix::CIccSparseMatrix function. This issue is fixed in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21486?
CVE-2026-21486 has critical severity due to the potential for remote code execution via heap-based buffer overflow.
How do I fix CVE-2026-21486?
To fix CVE-2026-21486, upgrade to a version of iccDEV later than 2.3.1.1 that has addressed these vulnerabilities.
What types of vulnerabilities are present in CVE-2026-21486?
CVE-2026-21486 contains Use After Free, Heap-based Buffer Overflow, Integer Overflow or Wraparound, and Out-of-bounds Write vulnerabilities.
What is affected by CVE-2026-21486?
CVE-2026-21486 affects iccDEV versions 2.3.1.1 and below.
Can CVE-2026-21486 lead to system compromise?
Yes, CVE-2026-21486 can lead to remote code execution, potentially allowing an attacker to compromise the system.