CVE-2026-41254: Integer Overflow
Last updated 2 June 2026
Other sources
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lcms2to a version that resolves this vulnerability.Fixed in 2.12~rc1-2+deb11u1Fixed in 2.14-2+deb12u1Fixed in 2.16-2+deb13u2Fixed in 2.17-1.1Fixed in 2.19.1-1 - Upgrade
Upgrade
Little CMS (lcms2)to a version that resolves this vulnerability.Fixed in 2.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41254?
CVE-2026-41254 is considered a critical vulnerability due to the potential for exploitation through an integer overflow.
How do I fix CVE-2026-41254?
To fix CVE-2026-41254, upgrade Little CMS (lcms2) to version 2.19 or later, which addresses the integer overflow issue.
What software is affected by CVE-2026-41254?
CVE-2026-41254 affects Little CMS (lcms2) versions up to and including 2.18.
What types of attacks can exploit CVE-2026-41254?
CVE-2026-41254 may be exploited to execute arbitrary code or cause a denial of service due to the integer overflow vulnerability.
Is there a workaround for CVE-2026-41254?
There are no effective workarounds for CVE-2026-41254, so upgrading to a patched version is recommended.