https://seclists.org/oss-sec/2026/q2/293: lcms2 <= 2.18 CubeSize() integer overflow: stock Ubuntu 24.04 Poppler / evince-thumbnailer / OpenJDK crashers (diffent triggers), no CVE
Published Apr 30, 2026
·Updated
Affected Software
7 affected components
Little Cms lcms2<=2.18
ubuntu/liblcms2-2<=2.18
debian/liblcms2-2<=2.18
fedora/lcms2<=2.18
alpine/lcms2<=2.18
homebrew/little-cms2<=2.18
Eclipse Adoptium Temurin=21.0.9
Frequently Asked Questions
1
What is the severity of CVE-2026-41254?
CVE-2026-41254 has been rescored to a severity of 7.5, categorized as High.
2
How does CVE-2026-41254 affect software?
CVE-2026-41254 causes crashes in applications that depend on Little CMS, specifically in Ubuntu's Poppler and evince-thumbnailer.
3
Which versions of lcms2 are affected by CVE-2026-41254?
The vulnerability affects all versions of lcms2 prior to 2.18.
4
How can I mitigate the risks associated with CVE-2026-41254?
To mitigate the risks, upgrade to the latest version of lcms2, which fixes the integer overflow issue.
5
What are the potential consequences of CVE-2026-41254 exploitation?
Exploitation of CVE-2026-41254 can lead to application crashes and potential denial of service.