CVE-2026-34548
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsigned 32-bit), which changes the value. This issue has been patched in version 2.3.1.6.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.2
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.16%
- CWE
- CWE-681
- Published
- 2026-03-31
- Last modified
- 2026-03-31
Affected products
- InternationalColorConsortium iccDEV
Weakness type
Related vulnerabilities
- CVE-2026-69438 — Microsoft JScript Remote Code Execution Vulnerability
- CVE-2026-84963 — Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
- CVE-2026-84966 — BSON element injection via NUL-embedded document keys in builder append
- CVE-2026-84970 — Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser
- CVE-2026-82522 — libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Truncation
- CVE-2026-82457 — su-exec through 0.3 Privilege Escalation via Numeric User ID
- CVE-2026-75145 — FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer
- CVE-2026-19879 — Io.undertow/undertow: undertow: http response header integrity issue due to character truncation