CVE-2026-31796: iccDEV has a heap-based buffer overflow in icCurvesFromXml()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in icCurvesFromXml() causing heap memory corruption or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31796?
CVE-2026-31796 is considered a high severity vulnerability due to the potential for heap memory corruption or application crashes.
How do I fix CVE-2026-31796?
To fix CVE-2026-31796, upgrade to version 2.3.1.5 or later of the iccDEV libraries.
What type of vulnerability is CVE-2026-31796?
CVE-2026-31796 is a heap-based buffer overflow vulnerability affecting the icCurvesFromXml() function.
What impact does CVE-2026-31796 have on applications?
The impact of CVE-2026-31796 may include application crashes and possible exploitation leading to arbitrary code execution.
Which versions of iccDEV are affected by CVE-2026-31796?
Versions of iccDEV prior to 2.3.1.5 are affected by CVE-2026-31796.