


Perceptive Security
SOC/SIEM Consultancy

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions prior to 2…
Published:
27 January 2026 at 23:00:00
Alert date:
28 January 2026 at 22:01:50
Source:
nvd.nist.gov
Supply Chain & Dependencies
iccDEV library versions prior to 2.3.1.2 contain an undefined behavior vulnerability when floating-point NaN values are converted to unsigned short integer types during ICC profile XML parsing. This issue can corrupt memory structures and potentially enable arbitrary code execution. The vulnerability affects users who process ICC color profiles and arises from unsafe incorporation of user-controllable input into ICC profile data. Version 2.3.1.2 contains a fix for this issue with no known workarounds available.
Technical details
Mitigation steps:
Affected products:
iccDEV
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-24856
https://github.com/InternationalColorConsortium/iccDEV/commit/5e53a5d25923b7794ba44e390e9b35d391f2b9c1
https://github.com/InternationalColorConsortium/iccDEV/issues/532
https://github.com/InternationalColorConsortium/iccDEV/pull/541
https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-w585-cv3v-c396
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
