CVE-2026-22255: iccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22255?
CVE-2026-22255 has been classified with a high severity due to its heap-buffer-overflow vulnerability.
How do I fix CVE-2026-22255?
To fix CVE-2026-22255, upgrade iccDEV to version 2.3.1.2 or later.
What versions of iccDEV are affected by CVE-2026-22255?
Versions of iccDEV prior to 2.3.1.2 are affected by CVE-2026-22255.
What is the nature of the vulnerability in CVE-2026-22255?
CVE-2026-22255 involves a heap-buffer-overflow in the function CIccCLUT::Init() which can lead to potential exploitation.
Is there a workaround for CVE-2026-22255?
No specific workaround is available for CVE-2026-22255; the recommended solution is to upgrade to the fixed version.