Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83081.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-83081
Upstream
Published
2026-04-18T07:16:10Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-41254 affecting package lcms2 for versions less than 2.15-2
Details

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

References

Affected packages

Azure Linux:3 / lcms2

Package

Name
lcms2
Purl
pkg:rpm/azure-linux/lcms2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.15-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83081.json"