{"id":"CVE-2026-27692","summary":"iccDEV has HBO in CIccTagTextDescription::Release()","details":"iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, causing a crash. Commit 29d088840b962a7cdd35993dfabc2cb35a049847 fixes the issue. No known workarounds are available.","aliases":["GHSA-3869-prw8-gjqr"],"modified":"2026-08-12T16:24:55.980758Z","published":"2026-02-25T14:40:22.740Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-170","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27692.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27692.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-3869-prw8-gjqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27692"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/609"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/29d088840b962a7cdd35993dfabc2cb35a049847"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/610"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"29d088840b962a7cdd35993dfabc2cb35a049847"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.3.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.4","v2.3.1.3","v2.3.1.2","v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"vanir_signatures_modified":"2026-08-12T16:24:55Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["86913730250778183184181698411207361463","157827830395535195793933853457565147834","246420076283357748384691267885886715776","35915357383867062396998767128116270556","132457638667244375284904915335545233419","148988581106556358121837670365706274566","313546694652836618565471386742395745681"],"threshold":0.9},"id":"CVE-2026-27692-a895c574","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/29d088840b962a7cdd35993dfabc2cb35a049847","target":{"file":"IccProfLib/IccTagBasic.cpp"}},{"id":"CVE-2026-27692-fec38814","signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/29d088840b962a7cdd35993dfabc2cb35a049847","target":{"file":"IccProfLib/IccTagBasic.cpp","function":"CIccTagTextDescription::GetBuffer"},"deprecated":false,"digest":{"function_hash":"158420873604993912036306051544258711187","length":223}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27692.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}