https://seclists.org/oss-sec/2026/q2/170: lcms2 <= 2.18 CubeSize() integer overflow: stock Ubuntu 24.04 Poppler / evince-thumbnailer / OpenJDK crashers (diffent triggers), no CVE
Published Apr 17, 2026
·Updated
Affected Software
7 affected components
Little Cms lcms2<=2.18
ubuntu/liblcms2-2=2.14-2build1
debian/liblcms2-2=2.16-2
fedora/lcms2=2.16
alpine/lcms2=2.17-r0
homebrew/little-cms2=2.18
Eclipse Adoptium Temurin=21.0.9
Frequently Asked Questions
1
What is the severity of lcms2 <= 2.18 CubeSize() integer overflow?
This vulnerability can cause crashes in several applications including evince-thumbnailer and OpenJDK on Ubuntu 24.04.
2
How do I fix lcms2 <= 2.18 CubeSize() integer overflow?
Upgrading to a patched version of lcms2 or applying available security updates for your distribution is recommended.
3
What applications are affected by lcms2 <= 2.18 CubeSize() integer overflow?
Evince-thumbnailer, Poppler, cups-filters, Okular, GIMP, and OpenJDK are affected by this vulnerability.
4
Is there a CVE associated with lcms2 <= 2.18 CubeSize() integer overflow?
There is no official CVE associated with this vulnerability.
5
What triggers the lcms2 <= 2.18 CubeSize() integer overflow?
A 992-byte PDF file triggers this integer overflow vulnerability causing crashes.