CVE-2026-30978: Heap-use-after-free in CIccCmm::AddXform()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIccCmm::AddXform() causing invalid vptr dereference and crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30978?
CVE-2026-30978 is classified as a critical vulnerability due to the potential for crashes and exploitation through heap-use-after-free.
How do I fix CVE-2026-30978?
To fix CVE-2026-30978, update your version of iccDEV to 2.3.1.5 or later.
What causes CVE-2026-30978?
CVE-2026-30978 is caused by a heap-use-after-free condition in the CIccCmm::AddXform() function of iccDEV.
In which versions of iccDEV is CVE-2026-30978 present?
CVE-2026-30978 affects all versions of iccDEV prior to 2.3.1.5.
What are the potential impacts of CVE-2026-30978?
The impacts of CVE-2026-30978 include application crashes and possible remote code execution due to invalid pointer dereferencing.