Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4568-1 | lcms2 security update |
Debian DSA |
DSA-6262-1 | lcms2 security update |
Thu, 07 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 22 Apr 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Littlecms little Cms
|
|
| CPEs | cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Littlecms little Cms
|
Mon, 20 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 18 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. | |
| First Time appeared |
Littlecms
Littlecms little Cms Color Engine |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Littlecms
Littlecms little Cms Color Engine |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-07T17:33:56.924Z
Reserved: 2026-04-18T06:43:13.323Z
Link: CVE-2026-41254
Updated: 2026-05-07T17:33:56.924Z
Status : Modified
Published: 2026-04-18T07:16:10.807
Modified: 2026-05-07T18:16:19.300
Link: CVE-2026-41254
OpenCVE Enrichment
Updated: 2026-04-20T14:00:08Z
Debian DLA
Debian DSA