CVE-2026-21673: iccDEV has Integer Overflow/Underflow in CIccXmlArrayType::ParseTextCountNum()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have overflows and underflows in CIccXmlArrayType::ParseTextCountNum(). This vulnerability affects users of the iccDEV library who process ICC color profiles. This issue is fixed in version 2.3.1.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21673?
CVE-2026-21673 is considered a high severity vulnerability due to its potential to cause memory corruption through overflows and underflows.
How do I fix CVE-2026-21673?
To fix CVE-2026-21673, upgrade iccDEV to version 2.3.2 or later, which addresses the identified vulnerabilities.
Who is affected by CVE-2026-21673?
Users of iccDEV library versions 2.3.1 and earlier that process ICC color profiles are affected by CVE-2026-21673.
What is the impact of CVE-2026-21673?
The impact of CVE-2026-21673 includes potential memory corruption, which could lead to application crashes or execution of arbitrary code.
What is the primary component vulnerable in CVE-2026-21673?
The primary component vulnerable in CVE-2026-21673 is the CIccXmlArrayType::ParseTextCountNum() function within the iccDEV library.