CVE-2026-41254

HIGH7.5EPSS 0.04%
Published: 4/18/2026Modified: 4/29/2026
Also known as:ALPINE-CVE-2026-41254

Description

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (2)