CVE-2026-30982: iccDEV has a heap out-of-bounds read in CIccPcsXform::pushXYZConvert()
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CIccPcsXform::pushXYZConvert() causing crash and potentially leaking memory contents. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 13, 58169
Event
via FIRST·01:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-30982?
CVE-2026-30982 has a severity rating that indicates a risk of crashing the application and potential memory leaks.
2
How do I fix CVE-2026-30982?
To fix CVE-2026-30982, update iccDEV to version 2.3.1.5 or later.
3
What type of vulnerability is CVE-2026-30982?
CVE-2026-30982 is classified as a heap out-of-bounds read vulnerability.
4
What software is affected by CVE-2026-30982?
CVE-2026-30982 affects iccDEV versions prior to 2.3.1.5.
5
What potential impact does CVE-2026-30982 have?
The impact of CVE-2026-30982 includes application crashes and possible leakage of sensitive memory contents.