Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2777 articles · 106414 vulns · 38/41 feeds (7d)
← Back to list
6.2
CVE-2026-34535EXPLOITED
internationalcolorconsortium · iccdev

iccDEV: SEGV in CIccTagArray::Cleanup()

Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a segmentation fault (SEGV) in CIccTagArray::Cleanup(). The issue is observable under UBSan/ASan as misaligned member access / misaligned pointer loads followed by an invalid read leading to process crash when running iccRoundTrip on a malicious profile. This issue has been patched in version 2.3.1.6.

Affected Products

VendorProductVersions
internationalcolorconsortiumiccdev< 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5

References

  • https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-965q-9pp6-6vw5(x_refsource_CONFIRM)
  • https://github.com/InternationalColorConsortium/iccDEV/issues/666(x_refsource_MISC)
  • https://github.com/InternationalColorConsortium/iccDEV/pull/683(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-34535 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CIccTagArray::Cleanup heap-based overflow (ID 666)
→ No new info (linked only)
CVSS 3.16.2 CRITICAL
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-122
PublishedMar 31, 2026
Last enriched6h agov2
Tags
CVE-2026-34535
Trending Score49
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34539EXP
iccDEV: HBO in CTiffImg::WriteLine()
Trending: 49
CRITICALCVE-2026-34534EXP
iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
Trending: 49
CRITICALCVE-2026-34540EXP
iccDEV: HBO in icMemDump()
Trending: 49
HIGHCVE-2026-34533EXP
iccDEV: UB in CIccCalculatorFunc::ApplySequence()
Trending: 46
HIGHCVE-2026-34546EXP
iccDEV: UB at TiffImg.h
Trending: 46

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026
Updated: affectedVersions, severity, activelyExploited, tags
Apr 1, 2026

Version History

v2
Last enriched 6h ago
v2Tier C6h ago

Updated affected versions to include 2.3.1.1 through 2.3.1.5, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploitedtags
via VulDB
v110h ago

Initial creation