A publicly disclosed flaw in Little CMS 2 (lcms2) affects all released versions through 2.18, where an integer overflow in CubeSize() can produce an undersized CLUT allocation and lead to out-of-bounds reads. The bug was reported as a check-after-multiply error and mapped to CWE-190 and CWE-125, with researchers showing that malformed PDFs or ICC profiles could crash applications that rely on liblcms2 for color processing.
The issue was reproduced against stock Ubuntu 24.04 components and other common builds, impacting Poppler tools, evince-thumbnailer, tumblerd, Okular, cups-filters pdftoraster, GIMP, lcms2 utilities, and OpenJDK 21, with additional confirmation on Temurin 21.0.9 for Windows and Homebrew little-cms2 2.18. Researchers also described a limited information disclosure primitive on Linux when ASLR is disabled. Although upstream reportedly fixed the flaw on the master branch in February and March 2026, no new release, advisory, or CVE had been issued at the time of disclosure, despite a GHSA filing and a MITRE CVE request.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
By the time of the public discussion, a GitHub Security Advisory filing and a MITRE CVE request had been submitted for the lcms2 CubeSize() flaw. However, no CVE had yet been assigned.
On oss-sec, a researcher publicly disclosed that all released lcms2 versions through 2.18 were affected by a CubeSize() integer overflow causing crashes in multiple consumers, including Poppler tools, evince-thumbnailer, Okular, cups-filters, GIMP, and OpenJDK. The disclosure also noted limited information disclosure potential on Linux and stated that no CVE or upstream release was available at the time.
Upstream Little CMS fixed the CubeSize() check-after-multiply integer overflow on the master branch in February and March 2026, addressing an undersized CLUT allocation that could lead to out-of-bounds reads. At that time, no new release or advisory had yet been issued.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.