CVE-2026-34553: iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (via CLUT dumping). This issue has been patched in version 2.3.1.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34553?
CVE-2026-34553 has a severity rating that necessitates immediate attention due to its potential to cause Denial of Service.
How do I fix CVE-2026-34553?
To mitigate CVE-2026-34553, update to version 2.3.1.6 or later of the iccDEV library.
What components are affected by CVE-2026-34553?
CVE-2026-34553 affects the CIccCLUT::Iterate() and CIccMBB::Describe() components in versions prior to 2.3.1.6.
What type of vulnerability is CVE-2026-34553?
CVE-2026-34553 is classified as a Denial of Service vulnerability in the iccDEV library.
Is there a workaround for CVE-2026-34553?
There are no specific workarounds recommended for CVE-2026-34553; the best solution is to upgrade to a fixed version.