CVE-2026-42798: Integer Overflow
Published Apr 30, 2026
·Updated
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
Affected Software
1 affected component
Little Cms lcms2>=2.16<=2.18
Event History
Apr 30, 2026
CVE Published
via MITRE·06:34 AM
Data Sourced
via MITRE·06:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42798?
CVE-2026-42798 has a high severity due to the integer overflow vulnerability that can lead to potential code execution.
2
How do I fix CVE-2026-42798?
To fix CVE-2026-42798, upgrade Little CMS (lcms2) to version 2.19 or later.
3
Which versions of Little CMS are affected by CVE-2026-42798?
CVE-2026-42798 affects Little CMS versions 2.16 through 2.18.
4
What component is vulnerable in CVE-2026-42798?
The ParseCube function in cmscgats.c is the component that contains the integer overflow vulnerability in CVE-2026-42798.
5
Is there a known exploit for CVE-2026-42798?
As of now, there are no public exploits reported for CVE-2026-42798, but the risk remains due to its nature.