CVE-2026-31795: iccDEV has a stack buffer overflow write in CIccXform3DLut::Apply()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow write in CIccXform3DLut::Apply() corrupting stack memory or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31795?
CVE-2026-31795 has a high severity level due to its potential to corrupt stack memory or cause application crashes.
How do I fix CVE-2026-31795?
To mitigate CVE-2026-31795, upgrade to version 2.3.1.5 or later of the iccDEV ICC Color Management Libraries.
What causes the CVE-2026-31795 vulnerability?
CVE-2026-31795 is caused by a stack buffer overflow in the CIccXform3DLut::Apply() function.
What applications are affected by CVE-2026-31795?
CVE-2026-31795 affects versions of the iccDEV ICC Color Management Libraries prior to 2.3.1.5.
Is CVE-2026-31795 exploitable remotely?
Yes, CVE-2026-31795 can be exploited remotely depending on the specific implementation of the affected libraries.