CVE-2026-31797: iccDEV has a heap out-of-bounds read in CTiffImg::ReadLine()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap out-of-bounds read in CTiffImg::ReadLine() when iccApplyProfiles processes a crafted TIFF image, causing memory disclosure or crash. This vulnerability is fixed in 2.3.1.5.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31797?
CVE-2026-31797 has been classified as a high severity vulnerability due to the potential for exploitation through crafted TIFF images.
How do I fix CVE-2026-31797?
To mitigate CVE-2026-31797, update to version 2.3.1.5 or later of iccDEV, as this version contains fixes for the vulnerability.
What type of vulnerability is CVE-2026-31797?
CVE-2026-31797 is characterized as a heap out-of-bounds read vulnerability affecting the CTiffImg::ReadLine() function in iccDEV.
Who is affected by CVE-2026-31797?
Users of iccDEV versions prior to 2.3.1.5 are affected by CVE-2026-31797.
What components are impacted by CVE-2026-31797?
CVE-2026-31797 affects the color management functionality within the iccDEV library when processing TIFF images.