CVE-2026-41254
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Faiblesse
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Produits concernés
- littlecms little_cms
Références
- https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/
- https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0
- https://github.com/mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc
- https://github.com/mm2/Little-CMS/security/advisories/GHSA-4xp6-rcgg-m9qq
- https://www.openwall.com/lists/oss-security/2026/04/17/16
- https://lists.debian.org/debian-lts-announce/2026/05/msg00014.html
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.