CVE-2026-30985
7.8International Color Consortium · iccDEV
A heap-based buffer overflow in the CIccMatrixMath::SetRange function of iccDEV prior to version 2.3.1.5 allows for memory corruption or application crashes.
Executive summary
A heap-based buffer overflow vulnerability in the International Color Consortium iccDEV library poses a significant risk of memory corruption and potential code execution.
Vulnerability
The flaw is a heap-based buffer overflow occurring within the CIccMatrixMath::SetRange function. The vulnerability is triggered when processing malformed ICC color management profiles, and it does not require prior authentication by the user.
Business impact
The exploitation of this vulnerability could lead to application crashes or arbitrary code execution, resulting in severe system compromise. Given the CVSS score of 7.8, this represents a high-severity risk to the integrity and availability of any system utilizing the vulnerable iccDEV library, potentially exposing sensitive data to unauthorized access.
Remediation
Immediate Action: Update the iccDEV library to version 2.3.1.5 or later to resolve the heap-based buffer overflow vulnerability.
Proactive Monitoring: Monitor application logs for segmentation faults or unexpected process terminations that may indicate exploitation attempts targeting the color profile parsing engine.
Compensating Controls: Restrict the ingestion of untrusted ICC color profiles from external or unverified sources to reduce the attack surface until the library can be updated.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The identified buffer overflow in iccDEV is a serious security defect that requires immediate remediation. Organizations using this library should prioritize the deployment of version 2.3.1.5 to eliminate the risk of memory corruption. Failure to patch these libraries leaves systems vulnerable to crashes and potential remote code execution by attackers providing malicious color profile files.
More International Color Consortium CVEs
Sources
- https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-f9wv-cq46-f9wg
- https://github.com/InternationalColorConsortium/iccDEV/issues/621
- https://github.com/InternationalColorConsortium/iccDEV/pull/636
- https://github.com/InternationalColorConsortium/iccDEV/releases/tag/v2.3.1.5