CVE-2026-24403: iccDEV Undefined Behavior in CIccProfile::CheckHeader() Leads to Integer Overflow
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, an integer overflow vulnerability exists in icValidateStatus CIccProfile::CheckHeader() when user-controllable input is incorporated into profile data unsafely. Tampering with tag tables, offsets, or size fields can trigger parsing errors, memory corruption, or DoS, potentially enabling arbitrary Code Execution or bypassing application logic. This issue has been fixed in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24403?
CVE-2026-24403 has a severity rating that indicates the potential for exploitation through integer overflow issues in the iccDEV ICC Profile Library.
How do I fix CVE-2026-24403?
To fix CVE-2026-24403, upgrade the iccDEV ICC Profile Library to version 2.3.1.2 or later.
What versions are affected by CVE-2026-24403?
CVE-2026-24403 affects iccDEV ICC Profile Library versions 2.3.1.1 and below.
What type of vulnerability is CVE-2026-24403?
CVE-2026-24403 is an integer overflow vulnerability in the check header functionality of the CIccProfile component.
Can CVE-2026-24403 lead to other security issues?
Yes, the integer overflow in CVE-2026-24403 could potentially be exploited to cause undefined behavior in applications utilizing the library.