CVE-2026-42798 PUBLISHED

Assigner: mitre
Reserved: 30.04.2026 Published: 30.04.2026 Updated: 30.04.2026

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
CVSS Score: 4

Product Status

Vendor littlecms
Product little cms color engine
Versions Default: unaffected
  • affected from 2.16 to 2.19 (excl.)

References

Problem Types

  • CWE-190 Integer Overflow or Wraparound CWE