CVE-2026-30987: iccDEV has a stack buffer overflow in CIccTagNum<(icTagTypeSignature)>::GetValues()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in CIccTagNum<>::GetValues() causing stack memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30987?
CVE-2026-30987 is classified as a high severity vulnerability due to the potential for stack memory corruption or crash.
How do I fix CVE-2026-30987?
To fix CVE-2026-30987, upgrade the iccDEV library to version 2.3.1.5 or later.
What is the impact of CVE-2026-30987?
The impact of CVE-2026-30987 includes possible application crashes and memory corruption leading to potential denial of service.
Who is affected by CVE-2026-30987?
Users of iccDEV versions prior to 2.3.1.5 are affected by CVE-2026-30987.
What components are involved in CVE-2026-30987?
CVE-2026-30987 involves the CIccTagNum<>::GetValues() function within the iccDEV color management library.