CVE-2026-34540 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile IccProfLib/IccUtil.cpp icMemDump heap-based overflow (ID 674)
A vulnerability classified as critical has been found in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. This vulnerability affects the function icMemDump in the library IccProfLib/IccUtil.cpp of the component ICC Color Profile Handler. This manipulation causes heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-34540. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.