https://seclists.org/oss-sec/2026/q2/294: lcms2 <= 2.18 CubeSize() integer overflow: stock Ubuntu 24.04 Poppler / evince-thumbnailer / OpenJDK crashers (diffent triggers), no CVE
Published Apr 30, 2026
·Updated
Affected Software
1 affected component
Little Cms lcms2<=2.18
Frequently Asked Questions
1
What is the severity of lcms2 <= 2.18 CubeSize() integer overflow?
The severity of lcms2 <= 2.18 CubeSize() integer overflow is high due to the associated crashes of multiple applications.
2
How do I fix lcms2 <= 2.18 CubeSize() integer overflow?
To fix lcms2 <= 2.18 CubeSize() integer overflow, upgrade to a patched version of the Little CMS library or apply relevant security patches.
3
Which applications are affected by lcms2 <= 2.18 CubeSize() integer overflow?
Applications affected by lcms2 <= 2.18 CubeSize() integer overflow include evince-thumbnailer, Poppler tools, cups-filters, Okular, and GIMP's PDF plug-in.
4
What triggers the lcms2 <= 2.18 CubeSize() integer overflow vulnerability?
The lcms2 <= 2.18 CubeSize() integer overflow vulnerability is triggered by the processing of specially crafted 992-byte PDF files.
5
Is there any workaround for lcms2 <= 2.18 CubeSize() integer overflow until a patch is available?
A temporary workaround for lcms2 <= 2.18 CubeSize() integer overflow is to avoid opening or processing 992-byte PDF files with the affected applications.