Description
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) via a null-pointer member call in CIccCombinedConnectionConditions::CIccCombinedConnectionConditions() (reported by UBSan as “member call on null pointer of type CIccTagSpectralViewingConditions”). The issue is reachable when running iccApplyNamedCmm with -PCC using a malformed .icc profile. This issue has been patched in version 2.3.1.6.
INFO
Published Date :
2026-03-31T22:04:16.675Z
Last Modified :
2026-04-01T18:53:18.285Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-34541 vulnerability.
| Vendors | Products |
|---|---|
| Internationalcolorconsortium |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34541.