CVE-2026-21687
7.1International Color Consortium · iccDEV
The iccDEV library contains an undefined behavior vulnerability in the CIccTagCurve constructor, which can lead to application instability when processing malicious International Color Consortium profiles.
Executive summary
A vulnerability in the International Color Consortium iccDEV library allows an attacker to trigger undefined behavior, potentially leading to a denial of service or integrity issues.
Vulnerability
This vulnerability involves improper input validation and reliance on undefined behavior within the CIccTagCurve::CIccTagCurve() function. It is exploitable by an unauthenticated attacker who provides a crafted ICC color profile for processing by the library.
Business impact
The vulnerability carries a CVSS score of 7.1, indicating a high severity risk. Successful exploitation could cause significant system instability or denial of service for applications relying on this library for color management. This could disrupt critical workflows that depend on accurate visual data processing or color profiling.
Remediation
Immediate Action: Update the iccDEV library to version 2.3.1.2 or later to incorporate the vendor provided patch.
Proactive Monitoring: Monitor application logs for unexpected crashes or errors occurring during the ingestion or processing of image files and color profiles.
Compensating Controls: If immediate patching is not feasible, restrict the ability of the application to process untrusted or externally sourced color profiles until the library is updated.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for denial of service and the high CVSS severity, organizations utilizing the iccDEV library should prioritize the update to version 2.3.1.2. Ensuring that all dependencies are current is essential to maintaining the stability and security of systems that perform image or color profile processing.