CVE-2026-21683: iccDEV has Type Confusion in icStatusCMM::CIccEvalCompare::EvaluateProfile()
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in icStatusCMM::CIccEvalCompare::EvaluateProfile(). This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21683?
CVE-2026-21683 is classified as a high severity vulnerability due to the potential for type confusion that could lead to exploitation.
How do I fix CVE-2026-21683?
To fix CVE-2026-21683, upgrade to iccDEV version 2.3.1.2 or later.
Which versions of iccDEV are affected by CVE-2026-21683?
CVE-2026-21683 affects all versions of iccDEV prior to 2.3.1.2.
What kind of vulnerability is CVE-2026-21683?
CVE-2026-21683 is a type confusion vulnerability in the icStatusCMM module of iccDEV.
Is there a workaround for CVE-2026-21683?
There is no documented workaround for CVE-2026-21683, so upgrading is the recommended action.