Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2701 articles · 106349 vulns · 38/41 feeds (7d)
← Back to list
6.2
CVE-2026-34537EXPLOITEDPATCHED
internationalcolorconsortium · iccdev

iccDEV: UB in CIccOpDefEnvVar::Exec()

Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) in CIccOpDefEnvVar::Exec() due to invalid enum values being loaded for icSigCmmEnvVar. The issue is observable under UBSan as a “load of value … not a valid value for type icSigCmmEnvVar”, indicating an invalid enum/type value being consumed during ICC profile processing. This issue has been patched in version 2.3.1.6.

Affected Products

VendorProductVersions
internationalcolorconsortiumiccdev< 2.3.1.6, 2.3.1.1, 2.3.1.2, 2.3.1.3, 2.3.1.4, 2.3.1.5

References

  • https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-3m63-c4jf-592f(x_refsource_CONFIRM)
  • https://github.com/InternationalColorConsortium/iccDEV/issues/670(x_refsource_MISC)
  • https://github.com/InternationalColorConsortium/iccDEV/pull/685(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-34537 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CIccOpDefEnvVar::Exec reliance on undefined, unspecified, or implementation-defined behavior (ID 670)
→ No new info (linked only)
CVSS 3.16.2 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available2.3.1.6
CWECWE-758
PublishedMar 31, 2026
Last enriched2h agov2
Tags
CVE-2026-34537
Trending Score48
Source articles2
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34534EXP
iccDEV: HBO in CIccMpeSpectralMatrix::Describe()
Trending: 51
CRITICALCVE-2026-34535EXP
iccDEV: SEGV in CIccTagArray::Cleanup()
Trending: 51
CRITICALCVE-2026-34540EXP
iccDEV: HBO in icMemDump()
Trending: 51
CRITICALCVE-2026-34539EXP
iccDEV: HBO in CTiffImg::WriteLine()
Trending: 51
HIGHCVE-2026-34553EXP
iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
Trending: 48

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Mar 31, 2026
Discovered by ZDM
Mar 31, 2026
Actively Exploited
Mar 31, 2026
Patch Available
Mar 31, 2026
Updated: affectedVersions, severity, activelyExploited, patchAvailable, tags
Apr 1, 2026

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated affected versions to include 2.3.1.1 through 2.3.1.5, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersionsseverityactivelyExploitedpatchAvailabletags
via VulDB
v16h ago

Initial creation