CVE-2026-34534: iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a heap-buffer-overflow (HBO) in CIccMpeSpectralMatrix::Describe(). The issue is observable under AddressSanitizer as an out-of-bounds heap read when running iccDumpProfile on a malicious profile. This issue has been patched in version 2.3.1.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34534?
CVE-2026-34534 is classified as a high severity vulnerability due to its potential to cause heap-buffer-overflow.
How do I fix CVE-2026-34534?
To fix CVE-2026-34534, update the iccDEV library to version 2.3.1.6 or later.
What versions of iccDEV are affected by CVE-2026-34534?
CVE-2026-34534 affects iccDEV versions prior to 2.3.1.6.
What exploits are possible with CVE-2026-34534?
Exploiting CVE-2026-34534 could allow an attacker to execute arbitrary code via crafted ICC profiles.
Who is impacted by CVE-2026-34534?
Users and developers utilizing affected versions of the iccDEV library for ICC color management are impacted by CVE-2026-34534.