iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-252",
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21492.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.3.1.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21492.json"
[
{
"target": {
"file": "IccProfLib/IccMpeBasic.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/b200a629ada310137d6ae5c53fc9e6d91a4b0dae",
"id": "CVE-2026-21492-1e5d5e17",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"91897618970245686490450952155680849346",
"310204963994269872223028762812705644224",
"321237813034687852851707764991362441290",
"234863764345641305646667469578030353207",
"276928595899742378317751921476465550289",
"238798108379404283792035669733633901886",
"213144379146512127689035988968401192638",
"331924531705696898454176460647496650083",
"251721812297716426727328630771213077367",
"242588624497853042351911821265142793364",
"211838766387345362264029146722639677203",
"279036054807935470724037602180519405762"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "IccProfLib/IccMpeBasic.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/e72361d215351cbac0002466c4f936e94d6a99e7",
"id": "CVE-2026-21492-4080ffa6",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"91897618970245686490450952155680849346",
"310204963994269872223028762812705644224",
"321237813034687852851707764991362441290",
"234863764345641305646667469578030353207",
"276928595899742378317751921476465550289",
"238798108379404283792035669733633901886",
"213144379146512127689035988968401192638",
"331924531705696898454176460647496650083",
"251721812297716426727328630771213077367",
"242588624497853042351911821265142793364",
"211838766387345362264029146722639677203",
"279036054807935470724037602180519405762"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "CIccMpeXmlToneMap::ParseXml",
"file": "IccXML/IccLibXML/IccMpeXml.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/e72361d215351cbac0002466c4f936e94d6a99e7",
"id": "CVE-2026-21492-425152d0",
"signature_version": "v1",
"digest": {
"length": 1991.0,
"function_hash": "339078371301493584872439500475851590428"
},
"signature_type": "Function"
},
{
"target": {
"function": "CIccMpeXmlToneMap::ParseXml",
"file": "IccXML/IccLibXML/IccMpeXml.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/b200a629ada310137d6ae5c53fc9e6d91a4b0dae",
"id": "CVE-2026-21492-752465ca",
"signature_version": "v1",
"digest": {
"length": 1991.0,
"function_hash": "339078371301493584872439500475851590428"
},
"signature_type": "Function"
},
{
"target": {
"file": "IccXML/IccLibXML/IccMpeXml.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/e72361d215351cbac0002466c4f936e94d6a99e7",
"id": "CVE-2026-21492-77d097ef",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"235747385737350213941027090926677216989",
"312092054282984063180473146040408152513",
"334349094473644955685819183189733886951",
"225268584887540309463256430919856820391",
"132387813535097794748267701159498901128",
"207787596348743330687391985203256663037",
"290485475990059227507365571968608735501",
"60970141130842081258808013895763373326"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "CIccMpeToneMap::Write",
"file": "IccProfLib/IccMpeBasic.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/b200a629ada310137d6ae5c53fc9e6d91a4b0dae",
"id": "CVE-2026-21492-88870e82",
"signature_version": "v1",
"digest": {
"length": 2026.0,
"function_hash": "324092508509928798149437840497609790480"
},
"signature_type": "Function"
},
{
"target": {
"function": "CIccMpeToneMap::Write",
"file": "IccProfLib/IccMpeBasic.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/e72361d215351cbac0002466c4f936e94d6a99e7",
"id": "CVE-2026-21492-ed3f3b98",
"signature_version": "v1",
"digest": {
"length": 2026.0,
"function_hash": "324092508509928798149437840497609790480"
},
"signature_type": "Function"
},
{
"target": {
"file": "IccXML/IccLibXML/IccMpeXml.cpp"
},
"deprecated": false,
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/b200a629ada310137d6ae5c53fc9e6d91a4b0dae",
"id": "CVE-2026-21492-f2b83943",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"235747385737350213941027090926677216989",
"312092054282984063180473146040408152513",
"334349094473644955685819183189733886951",
"225268584887540309463256430919856820391",
"132387813535097794748267701159498901128",
"207787596348743330687391985203256663037",
"290485475990059227507365571968608735501",
"60970141130842081258808013895763373326"
]
},
"signature_type": "Line"
}
]
"2026-08-12T15:32:47Z"