{"id":"CVE-2026-21679","summary":"iccDEV has heap-buffer-overflow vulnerability in CIccLocalizedUnicode::GetText()","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow in CIccLocalizedUnicode::GetText(). This issue has been patched in version 2.3.1.2.","aliases":["GHSA-h4wg-473g-p5wc"],"modified":"2026-08-12T15:31:34.899423Z","published":"2026-01-07T17:11:16.385Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21679.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21679.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-h4wg-473g-p5wc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21679"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/328"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/329"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"2eb25ab95f0db7664ec3850390b6f89e302e7039"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21679.json","vanir_signatures_modified":"2026-08-12T15:31:34Z","vanir_signatures":[{"target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccLocalizedUnicode::CIccLocalizedUnicode"},"deprecated":false,"digest":{"length":385,"function_hash":"98732991980806829245739794292369100049"},"id":"CVE-2026-21679-0bbba8c5","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039"},{"digest":{"function_hash":"93321947411116630832044997236289583804","length":409},"id":"CVE-2026-21679-10aa42c9","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039","target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccLocalizedUnicode::SetText"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"40729261289215385421587818254141149592","length":1159},"id":"CVE-2026-21679-1c216411","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039","target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccLocalizedUnicode::GetText"}},{"source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039","target":{"file":"IccProfLib/IccProfile.cpp","function":"CIccProfile::GetTagIO"},"deprecated":false,"digest":{"length":406,"function_hash":"324925524850127461554698137659801766658"},"id":"CVE-2026-21679-70f2b719","signature_type":"Function","signature_version":"v1"},{"target":{"file":"IccProfLib/IccTagBasic.cpp"},"deprecated":false,"digest":{"line_hashes":["308610124369132048986479763434589614542","222219003103545465390080574008929341163","43421079606789422276522663547482445806","5502935078107947210351750717484879269","101906203023845542634966760641595092402","278894066258925740371986592334949562775","311914155547825628910728325341337842418","217557065151122318751472162428789891180","264888981999317026282928010181669563079","177103180018434254393976484140830389502","7970618895788528894649676992749563910","270034592323916821187658113429100411995","230325550637693531525009488674997237783","9548440267746265774432938261337729887","338651656578692387484854384148274152120","252945493998732439882260311778584820201","51942857167960268466806281593701565755","119621949681510100210980063993228818264","252947751704109547467715991758496953131","339355824409049764874190198262132347513","6589079962386513939973437775289240608","335668071267678560249361227729481887533","224267724528009111023028785732218519347"],"threshold":0.9},"id":"CVE-2026-21679-8489ac2d","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039","target":{"file":"IccProfLib/IccProfile.cpp"},"deprecated":false,"digest":{"line_hashes":["150915969068097845236815972873632595985","28070254300955670214964224562031906844","230586545858662923219845220843491941365","231658414881867577588500381535582002197","224029439115472038488950949323537651617"],"threshold":0.9},"id":"CVE-2026-21679-a22a68cf"},{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/2eb25ab95f0db7664ec3850390b6f89e302e7039","target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccLocalizedUnicode::SetSize"},"deprecated":false,"digest":{"function_hash":"80515116825905287757659527875347878820","length":283},"id":"CVE-2026-21679-e7d8a094","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}