{"id":"CVE-2026-22861","summary":"iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Prior to 2.3.1.2, There is a heap-based buffer overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. The vulnerability is fixed in 2.3.1.2.","aliases":["GHSA-vr49-3vf8-7j5h"],"modified":"2026-08-12T15:32:52.261944Z","published":"2026-01-13T20:20:39.236Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-120","CWE-130","CWE-252"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22861.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22861.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-vr49-3vf8-7j5h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22861"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/fa9a364c01fc2e59eb2291e1f9b1c1359b7d5329"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/475"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/476"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"fa9a364c01fc2e59eb2291e1f9b1c1359b7d5329"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.2","v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22861.json","vanir_signatures_modified":"2026-08-12T15:32:52Z","vanir_signatures":[{"id":"CVE-2026-22861-6b39fa99","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/fa9a364c01fc2e59eb2291e1f9b1c1359b7d5329","target":{"file":"IccProfLib/IccMpeCalc.cpp"},"deprecated":false,"digest":{"line_hashes":["183794439653087648301504735998163838361","195786401335355551928033095423637882872","138512488586367622406722648200126205917","338224253996628081832859312424390674644","58545486708653191547349414205731225232","333171366369151587681731198120753417411","44362289721240854845648406182930949206","136801254970441164912807856487610199152"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/fa9a364c01fc2e59eb2291e1f9b1c1359b7d5329","target":{"file":"IccProfLib/IccMpeCalc.cpp","function":"CIccCalculatorFunc::DescribeSequence"},"deprecated":false,"digest":{"function_hash":"280744310389034761116838144604824110598","length":1957},"id":"CVE-2026-22861-c52671b8"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}