CVE-2026-21676: iccDEV has a Heap-based Buffer Overflow in its CIccMBB::Validate() function
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its CIccMBB::Validate function which checks tag data validity. This issue is fixed in version 2.3.1.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21676?
CVE-2026-21676 has been classified with a severity level that indicates a heap-based buffer overflow vulnerability in the affected versions.
How do I fix CVE-2026-21676?
To fix CVE-2026-21676, upgrade to version 2.3.1.1 or later of the iccDEV ICC color management libraries.
Which versions are affected by CVE-2026-21676?
CVE-2026-21676 affects all versions of iccDEV ICC color management libraries up to and including version 2.3.1.
What type of vulnerability is CVE-2026-21676?
CVE-2026-21676 is a heap-based buffer overflow vulnerability found in the CIccMBB::Validate function.
Is CVE-2026-21676 patched in the latest version of iccDEV?
Yes, CVE-2026-21676 has been patched in version 2.3.1.1 of the iccDEV ICC color management libraries.