Logo
vulnerabilityCVE-2026-41254
Name
CVE-2026-41254
Source
NVD ( link)Debian ( link)
Description
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lcms
Exploitable

Vulnerability Ratings#


4
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.16
Patched
buildroot
master
2.19.1
Not Affected
yocto
master
2.19.1
Not Affected
yocto
scarthgap
2.16
Patched

Resolved with patches#


lcms2 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix integer overflow in CubeSize()
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254
2
check for overflow
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254

lcms (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix integer overflow in CubeSize()
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254
2
check for overflow
Marti Maria <marti.maria@littlecms.com>
CVE-2026-41254