{"id":"CVE-2026-21489","summary":"iccDEV has Out-of-bounds Read and Integer Underflow (Wrap or Wraparound)","details":"iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and Integer Underflow (Wrap or Wraparound) vulnerabilities in its CIccCalculatorFunc::SequenceNeedTempReset function. This issue is fixed in version 2.3.1.2.","aliases":["GHSA-ph89-6q5h-wfw5"],"modified":"2026-08-12T16:24:49.460878Z","published":"2026-01-06T13:57:42.382Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21489.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21489.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-ph89-6q5h-wfw5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21489"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/cfabfe52c9c7eb0481b62c8aad56580bb11efdad"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"cfabfe52c9c7eb0481b62c8aad56580bb11efdad"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21489.json","vanir_signatures_modified":"2026-08-12T16:24:49Z","vanir_signatures":[{"digest":{"function_hash":"276425371092449740989887694375923434992","length":1763},"id":"CVE-2026-21489-5e8d6b83","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/cfabfe52c9c7eb0481b62c8aad56580bb11efdad","target":{"file":"IccProfLib/IccMpeCalc.cpp","function":"CIccCalculatorFunc::SequenceNeedTempReset"},"deprecated":false},{"id":"CVE-2026-21489-6efebb1d","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/cfabfe52c9c7eb0481b62c8aad56580bb11efdad","target":{"file":"IccProfLib/IccMpeCalc.cpp"},"deprecated":false,"digest":{"line_hashes":["198133994727567040155481425066656002119","81277960640926063151608651729712444225","25656865653103096820323002363719928095","173014904360340067639608466494915261332","79740448026072191458933195939712531404","50438246786389469216689591397946423998","194418884352918221129348805803278898859","267096762021885723145801712962112409698","233404004719165690134718188618383432561","222991644521799592140462302193364593881","219406030976280463287793526270677593018","9367437628751682938069033642161664051","161113669866394116494526044322153597082","19107305152624708394925347358073562222","52300177325693964894993086763359997273","130851256610775210485217386666574903705","88286402480473492140024571694625987647","127750512331458506918365113443538292203","276703235016309170084199506166915486279","3398904626528024993673470931214730850","215556304834196635495888176138153103746","294344989964658422292162326467296489486","27472561615841605345861181219566300171","265839138071473865744368472231191567214"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/cfabfe52c9c7eb0481b62c8aad56580bb11efdad","target":{"file":"IccProfLib/IccMpeCalc.cpp","function":"CIccCalculatorFunc::CheckUnderflowOverflow"},"deprecated":false,"digest":{"function_hash":"257041639393545773046239113187032240023","length":2662},"id":"CVE-2026-21489-e2465c42","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"}]}