CVE-2026-21682: iccDEV has heap-buffer-overflow in CIccXmlArrayType::ParseText()
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow in CIccXmlArrayType::ParseText(). This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21682?
CVE-2026-21682 is classified as a high-severity vulnerability due to its heap-buffer-overflow nature.
How do I fix CVE-2026-21682?
To fix CVE-2026-21682, upgrade iccDEV to version 2.3.1.2 or later.
What function is affected by CVE-2026-21682?
CVE-2026-21682 affects the function CIccXmlArrayType::ParseText() in iccDEV.
What type of vulnerability is CVE-2026-21682?
CVE-2026-21682 is a heap-buffer-overflow vulnerability that can lead to memory corruption.
Which versions of iccDEV are vulnerable to CVE-2026-21682?
Versions of iccDEV prior to 2.3.1.2 are vulnerable to CVE-2026-21682.