CVE-2026-31794: iccDEV has a SEGV in CIccCLUT::Interp3d()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a segmentation fault from invalid/wild pointer read in CIccCLUT::Interp3d() causing a denial of service. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31794?
CVE-2026-31794 has a severity rating that indicates it can lead to a denial of service due to a segmentation fault.
How do I fix CVE-2026-31794?
To fix CVE-2026-31794, upgrade to version 2.3.1.5 or later of iccDEV.
What causes the vulnerability in CVE-2026-31794?
The vulnerability in CVE-2026-31794 is caused by an invalid/wild pointer read in the CIccCLUT::Interp3d() function.
Which versions of iccDEV are affected by CVE-2026-31794?
Versions of iccDEV prior to 2.3.1.5 are affected by CVE-2026-31794.
Is CVE-2026-31794 a critical vulnerability?
CVE-2026-31794 is considered a critical vulnerability because it can cause a denial of service in affected applications.