CVE-2026-34542: iccDEV: SBO in CIccCalculatorFunc::Apply()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack-buffer-overflow (SBO) in CIccCalculatorFunc::Apply() when processed via iccApplyNamedCmm. Under AddressSanitizer, the failure is reported as a 4-byte write stack-buffer-overflow in IccProfLib/IccMpeCalc.cpp:3873, reachable through the MPE calculator / curve set initialization path. This issue has been patched in version 2.3.1.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34542?
CVE-2026-34542 has a medium severity rating due to the potential for a stack-buffer overflow.
How do I fix CVE-2026-34542?
To fix CVE-2026-34542, upgrade to iccDEV version 2.3.1.6 or later.
What is affected by CVE-2026-34542?
CVE-2026-34542 affects iccDEV versions prior to 2.3.1.6.
What type of vulnerability is CVE-2026-34542?
CVE-2026-34542 is a stack-buffer overflow vulnerability.
What actions should be taken if CVE-2026-34542 is exploited?
If CVE-2026-34542 is exploited, it is important to immediately update to the patched version and assess any potential damage.