CVE-2026-30986: iccDEV has a heap-based buffer overflow write in CIccCLUT::Interp3d()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow write in CIccMatrixMath::SetRange() causing memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30986?
CVE-2026-30986 has a high severity due to the potential for heap-based buffer overflow leading to memory corruption or application crashes.
What causes CVE-2026-30986?
CVE-2026-30986 is caused by a heap-based buffer overflow write in the CIccMatrixMath::SetRange() function.
How do I fix CVE-2026-30986?
To fix CVE-2026-30986, upgrade to the latest version of iccDEV beyond 2.3.1.5.
What versions of iccDEV are affected by CVE-2026-30986?
CVE-2026-30986 affects iccDEV versions prior to 2.3.1.5.
What is the impact of CVE-2026-30986?
The impact of CVE-2026-30986 includes potential memory corruption and application crashes during the use of ICC color management profiles.