{"id":"CVE-2026-21501","summary":"Stack Overflow in iccDEV Calculator Parser","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the calculator parser. This issue has been patched in version 2.3.1.2.","aliases":["GHSA-x7hw-h22p-2x4w"],"modified":"2026-08-12T15:32:47.763219Z","published":"2026-01-07T17:09:54.802Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21501.json"},"references":[{"type":"WEB","url":"https://github.com/InternationalColorConsortium/iccDEV/blob/8e71f0a701abcbd554725ba7b70258203e682a61/IccProfLib/IccMpeCalc.cpp#L4588"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21501.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-x7hw-h22p-2x4w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21501"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/365"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/798be59011649a26a529600cc3cd56437634d3d0"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/f3056ed99935d479091470127ad16f8be1912bb7"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/413"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"798be59011649a26a529600cc3cd56437634d3d0"},{"fixed":"f3056ed99935d479091470127ad16f8be1912bb7"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21501.json","vanir_signatures_modified":"2026-08-12T15:32:47Z","vanir_signatures":[{"digest":{"line_hashes":["231107529110788856309907126291783157788","161176965976568014711517514878013992458","195226841306352828665520691802519044346","258808155130892684068836446020679497619","62576967824330684153314836508502563002","293887360677326865650941143789674312260","293887360677326865650941143789674312260","100200276465126701985206811874671530820","236661440056914965237264616520945300735","224505869152383567782745202262011678766","165785839894601301150504225033586879583","93790919193646495740964850142039417092","77797417551268429888689062322636156644","95228742920805281926598866148585604764","177934689300927493459842396128368368332","74735536288198572433107791968812074008","41756226384930565676309116574648943602","161362180200632804595970055936333502865","293935299590388350229698100181320638999","273859202331785465302973965200470893406","37312650806963180324624530872416678737","162551607843446018948133873885630707221","292869934778410003356821852210414230723","254024513224462659660939676508533951017","88153887051376634135637745576236523661","158865535306128115666420415226195334283","336106093537596221304316875723869093302","219900186866955520284259921899508616054"],"threshold":0.9},"id":"CVE-2026-21501-4ff05c22","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/f3056ed99935d479091470127ad16f8be1912bb7","target":{"file":"IccProfLib/IccMpeCalc.cpp"},"deprecated":false},{"source":"https://github.com/internationalcolorconsortium/iccdev/commit/798be59011649a26a529600cc3cd56437634d3d0","target":{"file":"IccProfLib/IccMpeCalc.cpp"},"deprecated":false,"digest":{"line_hashes":["231107529110788856309907126291783157788","161176965976568014711517514878013992458","195226841306352828665520691802519044346","258808155130892684068836446020679497619","62576967824330684153314836508502563002","293887360677326865650941143789674312260","293887360677326865650941143789674312260","100200276465126701985206811874671530820","236661440056914965237264616520945300735","224505869152383567782745202262011678766","165785839894601301150504225033586879583","93790919193646495740964850142039417092","77797417551268429888689062322636156644","95228742920805281926598866148585604764","177934689300927493459842396128368368332","74735536288198572433107791968812074008","41756226384930565676309116574648943602","161362180200632804595970055936333502865","293935299590388350229698100181320638999","273859202331785465302973965200470893406","37312650806963180324624530872416678737","162551607843446018948133873885630707221","292869934778410003356821852210414230723","254024513224462659660939676508533951017","88153887051376634135637745576236523661","158865535306128115666420415226195334283","336106093537596221304316875723869093302","219900186866955520284259921899508616054"],"threshold":0.9},"id":"CVE-2026-21501-f5d997ba","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"201824775077096681480137413787126580189","length":1951},"id":"CVE-2026-21501-f8f888b0","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/798be59011649a26a529600cc3cd56437634d3d0","target":{"file":"IccProfLib/IccMpeCalc.cpp","function":"CIccMpeCalculator::Read"}},{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/f3056ed99935d479091470127ad16f8be1912bb7","target":{"file":"IccProfLib/IccMpeCalc.cpp","function":"CIccMpeCalculator::Read"},"deprecated":false,"digest":{"function_hash":"201824775077096681480137413787126580189","length":1951},"id":"CVE-2026-21501-fa94b15f","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}