Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83081.json"