CVE-2026-30979: iccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp() triggered with local user interaction causing memory corruption/crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30979?
CVE-2026-30979 is classified as a high severity vulnerability due to the potential for exploitation through a heap-based buffer overflow.
How do I fix CVE-2026-30979?
To fix CVE-2026-30979, update the iccDEV software to version 2.3.1.5 or later.
What types of attacks can CVE-2026-30979 enable?
CVE-2026-30979 can enable remote code execution attacks if successfully exploited.
Who is affected by CVE-2026-30979?
Users of iccDEV versions prior to 2.3.1.5 are affected by CVE-2026-30979.
What component of iccDEV is vulnerable in CVE-2026-30979?
The vulnerability in CVE-2026-30979 is found in the CIccCalculatorFunc::InitSelectOp() function.