CVE-2026-30980: iccDEV has a stack overflow in CIccBasicStructFactory::CreateStruct()
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack overflow in CIccBasicStructFactory::CreateStruct() causing uncontrolled recursion/stack exhaustion and crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·02:54 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-30980?
CVE-2026-30980 is classified as a high-severity vulnerability due to its potential for causing stack exhaustion.
2
How do I fix CVE-2026-30980?
To fix CVE-2026-30980, update to version 2.3.1.5 or later of the iccDEV software.
3
What type of vulnerability is CVE-2026-30980?
CVE-2026-30980 is a stack overflow vulnerability that leads to uncontrolled recursion.
4
Which versions of iccDEV are affected by CVE-2026-30980?
CVE-2026-30980 affects iccDEV versions prior to 2.3.1.5.
5
What are the potential consequences of CVE-2026-30980?
The potential consequences of CVE-2026-30980 include application crashes and possible denial of service due to stack exhaustion.