CVE-2026-30985: iccDEV has a heap-based buffer overflow write in CIccMatrixMath::SetRange()
Published Mar 10, 2026
·Updated
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow write in CIccMatrixMath::SetRange() causing memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
2 affected components
iccDEV iccDEV<2.3.1.5
Color iccDEV<2.3.1.5
Remediation
Event History
Mar 10, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 6, 58175
Event
via FIRST·07:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-30985?
CVE-2026-30985 has a critical severity rating due to its heap-based buffer overflow vulnerability.
2
How do I fix CVE-2026-30985?
To fix CVE-2026-30985, update to iccDEV version 2.3.1.5 or later.
3
What causes CVE-2026-30985?
CVE-2026-30985 is caused by a heap-based buffer overflow in the CIccMatrixMath::SetRange() function.
4
What are the potential impacts of CVE-2026-30985?
The potential impacts of CVE-2026-30985 include memory corruption and application crashes.
5
Which versions of iccDEV are affected by CVE-2026-30985?
Versions of iccDEV prior to 2.3.1.5 are affected by CVE-2026-30985.