ZeroHour

CVE-2026-41254

PoC
CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
Description

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Vendors
littlecms
Products
little cms
Weakness
CWE-696, CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.