CVE-2026-21504

MEDIUM

Color Iccdev < 2.3.1.2 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap buffer overflow in the ToneMap parser. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 6.6
EPSS 0.0002
EPSS Percentile 5.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122 CWE-193 CWE-787
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026