CVE-2026-21675: iccDEV has a Use After Free vulnerability in CIccCmm class via improper hint manager object deletion
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulnerability in the CIccXform::Create() function, where it deletes the hint. This issue is fixed in version 2.3.1.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21675?
CVE-2026-21675 has been rated as a moderate severity vulnerability due to its potential impact on application stability.
How do I fix CVE-2026-21675?
To mitigate CVE-2026-21675, update to version 2.3.1.1 or later of the iccDEV ICC color management libraries.
Which versions of iccDEV are affected by CVE-2026-21675?
CVE-2026-21675 affects versions 2.3.1 and below of the iccDEV ICC color management libraries.
What is the nature of the vulnerability in CVE-2026-21675?
CVE-2026-21675 is a Use After Free vulnerability that occurs in the CIccXform::Create() function.
Who is responsible for the iccDEV ICC color management libraries related to CVE-2026-21675?
The iccDEV ICC color management libraries, including the vulnerability CVE-2026-21675, are maintained by the International Color Consortium.