CVE-2026-34554: iccDEV: HBO in CIccApplyCmmSearch::costFunc()
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) in CIccApplyCmmSearch::costFunc() can be triggered via malformed JSON configuration input to the iccApplySearch tool. AddressSanitizer reports an out-of-bounds READ of size 8 originating from CIccApplyCmmSearch::costFunc(CIccSearchVec&) at IccProfLib/IccCmmSearch.cpp:112:5. This issue has been patched in version 2.3.1.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34554?
CVE-2026-34554 has been identified as a high severity vulnerability due to the potential for arbitrary code execution resulting from the heap-buffer-overflow.
How do I fix CVE-2026-34554?
To mitigate CVE-2026-34554, upgrade to iccDEV version 2.3.1.6 or later, which includes a patch for the vulnerability.
What type of vulnerability is CVE-2026-34554?
CVE-2026-34554 is classified as a heap-buffer-overflow, which can lead to security risks if exploited.
Which versions of iccDEV are affected by CVE-2026-34554?
CVE-2026-34554 affects all versions of iccDEV prior to 2.3.1.6.
What can happen if CVE-2026-34554 is exploited?
Exploitation of CVE-2026-34554 can allow an attacker to execute arbitrary code on the affected system, potentially leading to full system compromise.