Logo
vulnerabilityCVE-2026-42798
Name
CVE-2026-42798
Source
NVD ( link)Debian ( link)
Description
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
lcms2
Patched

Vulnerability Ratings#


4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
2.19.1
Not Affected
yocto
kirkstone
2.13.1
Not Affected
yocto
master
2.19.1
Not Affected
yocto
scarthgap
2.16
Patched

Resolved with patches#


lcms2 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix for ParseCube integer overflow in LUT allocation
Marti Maria <marti.maria@littlecms.com>
CVE-2026-42798

lcms (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix for ParseCube integer overflow in LUT allocation
Marti Maria <marti.maria@littlecms.com>
CVE-2026-42798