CVE-2026-22047: iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22047?
CVE-2026-22047 is classified as a high-severity vulnerability due to the potential for a heap-buffer overflow.
How do I fix CVE-2026-22047?
To mitigate CVE-2026-22047, update the iccDEV software to version 2.3.1.2 or later.
What versions of iccDEV are affected by CVE-2026-22047?
Versions of iccDEV prior to 2.3.1.2 are affected by CVE-2026-22047.
What kind of vulnerability is CVE-2026-22047?
CVE-2026-22047 is a heap-buffer-overflow vulnerability found in the SIccCalcOp::Describe() function.
What impact does CVE-2026-22047 have on my system?
CVE-2026-22047 can lead to potential system crashes or arbitrary code execution, posing serious security risks.