CVE-2026-27692: iccDEV has HBO in CIccTagTextDescription::Release()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27692?
CVE-2026-27692 has a high severity rating due to the potential for heap-buffer-overflow vulnerabilities that can lead to information disclosure.
How do I fix CVE-2026-27692?
To fix CVE-2026-27692, update to version 2.3.1.5 or later of the iccDEV libraries.
What is the impact of CVE-2026-27692 on affected software?
CVE-2026-27692 can lead to data corruption or application crashes due to improper handling of ICC profile XML text descriptions.
Which versions of iccDEV are affected by CVE-2026-27692?
CVE-2026-27692 affects all versions of iccDEV up to and including 2.3.1.4.
Can CVE-2026-27692 be exploited remotely?
Yes, CVE-2026-27692 can potentially be exploited remotely if an attacker manipulates ICC profile data.