CVE-2026-41254

NameCVE-2026-41254
DescriptionLittle CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4568-1, DLA-4702-1, DLA-4703-1, DSA-6262-1
Debian Bugs1134335

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lcms2 (PTS)bullseye2.12~rc1-2vulnerable
bullseye (security)2.12~rc1-2+deb11u1fixed
bookworm, bookworm (security)2.14-2+deb12u1fixed
trixie (security), trixie2.16-2+deb13u2fixed
forky, sid2.19.1-1fixed
openjdk-11 (PTS)bullseye11.0.24+8-2~deb11u1vulnerable
bullseye (security)11.0.32+9-2~deb11u1fixed
sid11.0.32+9-2fixed
openjdk-17 (PTS)bullseye17.0.12+7-2~deb11u1vulnerable
bullseye (security)17.0.20+8-1~deb11u1fixed
bookworm17.0.19+10-1~deb12u2vulnerable
bookworm (security)17.0.20+8-1~deb12u1fixed
sid17.0.20+8-1fixed
openjdk-21 (PTS)trixie (security), trixie21.0.11+10-1~deb13u2vulnerable
sid21.0.12+8-1fixed
openjdk-25 (PTS)trixie (security), trixie25.0.3+9-2~deb13u1vulnerable
forky, sid25.0.4+7-1fixed
openjdk-26 (PTS)forky26+35-2vulnerable
sid26.0.2+10-2fixed
openjdk-8 (PTS)sid8u492-ga-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lcms2sourcebullseye2.12~rc1-2+deb11u1DLA-4568-1
lcms2sourcebookworm2.14-2+deb12u1DSA-6262-1
lcms2sourcetrixie2.16-2+deb13u2DSA-6262-1
lcms2source(unstable)2.17-1.11134335
openjdk-11sourcebullseye11.0.32+9-2~deb11u1DLA-4702-1
openjdk-11source(unstable)11.0.32+9-1
openjdk-17sourcebullseye17.0.20+8-1~deb11u1DLA-4703-1
openjdk-17sourcebookworm17.0.20+8-1~deb12u1DLA-4703-1
openjdk-17source(unstable)17.0.20+8-1
openjdk-21source(unstable)21.0.12+8-1
openjdk-25source(unstable)25.0.4+7-1
openjdk-26source(unstable)26.0.2+10-1
openjdk-8source(unstable)(unfixed)

Notes

https://openjdk.org/groups/vulnerability/advisories/2026-07-21
https://www.openwall.com/lists/oss-security/2026/04/17/16
https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/
Fixed by: https://github.com/mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0 (master)
Fixed by: https://github.com/mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc (master)

Search for package or bug name: Reporting problems