yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-42798
Component Overview
Vulnerability Overview
Name
CVE-2026-42798
Source
NVD (
link
)
Debian (
link
)
Description
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
CWEs
CWE-190
Published Date
Apr 30, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
lcms
Patched
Vulnerability Ratings
#
4
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
lcms2
buildroot
2025.02.x
2.16
Patched
lcms2
buildroot
master
2.19.1
Not Affected
lcms
yocto
kirkstone
2.13.1
Not Affected
lcms
yocto
master
2.19.1
Not Affected
Resolved with patches
#
lcms2 (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Fix for ParseCube integer overflow in LUT allocation
Marti Maria <marti.maria@littlecms.com>
CVE-2026-42798
lcms (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix for ParseCube integer overflow in LUT allocation
Marti Maria <marti.maria@littlecms.com>
CVE-2026-42798