CVE-2026-30981: iccDEV has a heap-buffer-overflow read in CIccXmlArrayType<>
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-buffer-overflow read in CIccXmlArrayType<>::DumpArray() causing out-of-bounds read and/or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·10:55 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-30981?
CVE-2026-30981 has a high severity due to its potential to cause crashes through heap-buffer-overflow reads.
2
How do I fix CVE-2026-30981?
To fix CVE-2026-30981, upgrade to version 2.3.1.5 or later of iccDEV.
3
What causes the vulnerability CVE-2026-30981?
CVE-2026-30981 is caused by a heap-buffer-overflow read in the DumpArray() function of CIccXmlArrayType<> in iccDEV.
4
What is the impact of CVE-2026-30981?
The impact of CVE-2026-30981 includes potential out-of-bounds read and system crashes when using affected versions of iccDEV.
5
Which versions of iccDEV are affected by CVE-2026-30981?
CVE-2026-30981 affects versions of iccDEV prior to 2.3.1.5.