yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-41254
Component Overview
Vulnerability Overview
Name
CVE-2026-41254
Source
NVD (
link
)
Debian (
link
)
Description
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CWEs
CWE-696
CWE-190
Published Date
Apr 18, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/
Exploit
https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0
Patch
https://github.com/mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc
Patch
https://github.com/mm2/Little-CMS/security/advisories/GHSA-4xp6-rcgg-m9qq
Broken Link
https://www.openwall.com/lists/oss-security/2026/04/17/16
Mailing List
Analysis
#
Affected Component
Analysis
lcms
Exploitable
Vulnerability Ratings
#
4
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
lcms2
buildroot
2025.02.x
2.16
Patched
lcms2
buildroot
master
2.19.1
Not Affected
lcms
yocto
master
2.19.1
Not Affected
lcms
yocto
scarthgap
2.16
Patched
Resolved with patches
#
lcms2 (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Fix integer overflow in CubeSize()
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254
2
check for overflow
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254
lcms (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix integer overflow in CubeSize()
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254
2
check for overflow
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254