Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-41254

Опубликовано: 18 апр. 2026
Источник: debian
EPSS Низкий

Описание

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lcms2fixed2.17-1.1package
openjdk-26fixed26.0.2+10-1package
openjdk-25fixed25.0.4+7-1package
openjdk-21fixed21.0.12+8-1package
openjdk-17fixed17.0.20+8-1package
openjdk-11fixed11.0.32+9-1package
openjdk-8unfixedpackage

Примечания

  • https://openjdk.org/groups/vulnerability/advisories/2026-07-21

  • https://www.openwall.com/lists/oss-security/2026/04/17/16

  • https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/

  • Fixed by: https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0 (master)

  • Fixed by: https://github.com/mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc (master)

EPSS

Процентиль: 29%
0.00365
Низкий

Связанные уязвимости

CVSS3: 4
ubuntu
3 месяца назад

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVSS3: 6.1
redhat
3 месяца назад

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVSS3: 4
nvd
3 месяца назад

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

CVSS3: 4
msrc
3 месяца назад

Описание отсутствует

CVSS3: 4
github
3 месяца назад

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

EPSS

Процентиль: 29%
0.00365
Низкий