Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 18 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. | |
| First Time appeared |
Littlecms
Littlecms little Cms Color Engine |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Littlecms
Littlecms little Cms Color Engine |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-18T06:43:42.580Z
Reserved: 2026-04-18T06:43:13.323Z
Link: CVE-2026-41254
No data.
Status : Received
Published: 2026-04-18T07:16:10.807
Modified: 2026-04-18T07:16:10.807
Link: CVE-2026-41254
No data.
OpenCVE Enrichment
No data.
Weaknesses