CVE-2026-21679: iccDEV has heap-buffer-overflow vulnerability in CIccLocalizedUnicode::GetText()
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow in CIccLocalizedUnicode::GetText(). This issue has been patched in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21679?
CVE-2026-21679 has been assigned a critical severity rating due to its potential for heap-buffer overflow, which could lead to code execution.
How do I fix CVE-2026-21679?
To fix CVE-2026-21679, users should upgrade to version 2.3.1.2 or later of the iccDEV software, where the vulnerability has been patched.
What vulnerability does CVE-2026-21679 address?
CVE-2026-21679 addresses a heap-buffer overflow vulnerability in the function CIccLocalizedUnicode::GetText() within iccDEV.
Which versions of iccDEV are affected by CVE-2026-21679?
Versions of iccDEV prior to 2.3.1.2 are affected by CVE-2026-21679.
Is CVE-2026-21679 being actively exploited?
As of now, there have been no confirmed reports of CVE-2026-21679 being actively exploited in the wild.