iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer, the issue is reported as invalid left shift operations on icUInt32Number (unsigned 32-bit) where the shifted value “cannot be represented” in that type. This issue has been patched in version 2.3.1.6.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
|
| Vendors & Products |
Internationalcolorconsortium
Internationalcolorconsortium iccdev |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer, the issue is reported as invalid left shift operations on icUInt32Number (unsigned 32-bit) where the shifted value “cannot be represented” in that type. This issue has been patched in version 2.3.1.6. | |
| Title | iccDEV: UB at IccUtil.cpp | |
| Weaknesses | CWE-758 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-31T22:11:21.090Z
Updated: 2026-04-03T16:41:44.818Z
Reserved: 2026-03-30T16:31:39.264Z
Link: CVE-2026-34549
Updated: 2026-04-03T16:41:40.840Z
Status : Undergoing Analysis
Published: 2026-03-31T23:17:09.770
Modified: 2026-04-01T14:23:37.727
Link: CVE-2026-34549
No data.