CVE-2026-21504: Heap Buffer Overflow in iccDEV ToneMap Parser
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This issue has been patched in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21504?
CVE-2026-21504 is classified as a high severity vulnerability due to its potential for exploitation through heap buffer overflow.
How do I fix CVE-2026-21504?
To address CVE-2026-21504, upgrade to version 2.3.1.2 or later of iccDEV, which includes a patch for this vulnerability.
What are the risks associated with CVE-2026-21504?
The risks of CVE-2026-21504 include possible remote code execution and system compromise resulting from the heap buffer overflow.
Which versions of iccDEV are affected by CVE-2026-21504?
CVE-2026-21504 affects all versions of iccDEV prior to 2.3.1.2.
Is there a known exploit for CVE-2026-21504?
As of now, there is no publicly acknowledged exploit for CVE-2026-21504, but it is advisable to apply the patch promptly to mitigate risks.