CVE-2026-31792: iccDEV has a null pointer dereference in CIccTagXmlStruct::ParseTag()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a null pointer dereference in CIccTagXmlStruct::ParseTag() causing a segmentation fault or denial of service. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31792?
CVE-2026-31792 has a severity rating that indicates it can cause a segmentation fault or denial of service.
How do I fix CVE-2026-31792?
To fix CVE-2026-31792, update to version 2.3.1.5 or later of the iccDEV ICC Color Management Library.
What causes the null pointer dereference in CVE-2026-31792?
The null pointer dereference in CVE-2026-31792 is caused by a flaw in the CIccTagXmlStruct::ParseTag() function.
Which versions of the ICC Color Management Library are affected by CVE-2026-31792?
Versions of the ICC Color Management Library prior to 2.3.1.5 are affected by CVE-2026-31792.
What type of issue is CVE-2026-31792 classified as?
CVE-2026-31792 is classified as a vulnerability that can lead to segmentation faults or denial of service.