CVE-2026-21688: iccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cpp
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21688?
CVE-2026-21688 is classified as a severe vulnerability due to its Type Confusion nature, which can lead to arbitrary code execution.
How do I fix CVE-2026-21688?
To fix CVE-2026-21688, upgrade to version 2.3.1.2 or later of the iccDEV libraries.
What does CVE-2026-21688 affect?
CVE-2026-21688 affects iccDEV versions prior to 2.3.1.2, which are used for managing ICC color profiles.
What is the nature of the vulnerability in CVE-2026-21688?
The vulnerability in CVE-2026-21688 involves a Type Confusion flaw within the `SIccCalcOp::ArgsPushed()` function.
Who is affected by CVE-2026-21688?
Developers and users of the iccDEV software who are using versions before 2.3.1.2 are affected by CVE-2026-21688.