CVE-2026-27691

Source
https://cve.org/CVERecord?id=CVE-2026-27691
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27691.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27691
Aliases
  • GHSA-4gfj-4cjh-53v5
Published
2026-02-25T14:36:16.803Z
Modified
2026-03-03T02:56:38.330322Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218
Details

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication triggers undefined behavior, potentially causing crashes or incorrect ICC profile generation when processing crafted/large cube inputs. Commit 43ae18dd69fc70190d3632a18a3af2f3da1e052a fixes the issue. No known workarounds are available.

Database specific
{
    "cwe_ids": [
        "CWE-190",
        "CWE-681"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27691.json"
}
References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27691.json"