CVE-2026-27692

HIGH

iccDEV <=2.3.1.4 - Memory Corruption

Title source: llm
STIX 2.1

Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787 CWE-170 CWE-125
Status published
Products (1)
color/iccdev < 2.3.1.4
Published Feb 25, 2026
Tracked Since Feb 25, 2026