CVE-2026-42798

Published: May 6, 2026Last modified: May 7, 2026

Description

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

Severity score breakdown

ParameterValue
Base score4
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactLOW
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlcms2Not affected (2.14-r0)
25 LTSlcms2Fixed (2.19-r0)
Streamlcms2Fixed (2.19-r0)

References

ON THIS PAGE