https://seclists.org/oss-sec/2026/q2/172: lcms2 <= 2.18 CubeSize() integer overflow: stock Ubuntu 24.04 Poppler / evince-thumbnailer / OpenJDK crashers (diffent triggers), no CVE
Published Apr 18, 2026
·Updated
Affected Software
7 affected components
Little-CMS lcms2<=2.18
ubuntu/liblcms2-2=2.14-2build1
debian/liblcms2-2=2.16-2
fedora/lcms2=2.16
alpine/lcms2=2.17-r0
homebrew/little-cms2=2.18
Adoptium Temurin=21.0.9
Frequently Asked Questions
1
What is the severity of CVE-2026-41254?
CVE-2026-41254 has a high severity due to its potential to cause crashes in multiple applications on Ubuntu 24.04.
2
How do I fix CVE-2026-41254?
To fix CVE-2026-41254, update Little-CMS to a version that addresses the integer overflow issue.
3
What applications are affected by CVE-2026-41254?
CVE-2026-41254 affects evince-thumbnailer, Poppler tools, and several other stock Ubuntu 24.04 applications.
4
What triggers CVE-2026-41254?
CVE-2026-41254 is triggered by a specifically crafted 992-byte PDF that causes crashes.
5
Is there a known workaround for CVE-2026-41254?
Currently, there are no known workarounds for CVE-2026-41254 other than applying the update once available.