Little CMS could be made to crash or run programs if it opened a
specially crafted ICC profile.
Software Description:
- lcms2: Little CMS color management library
Details:
It was discovered that Little CMS incorrectly handled certain malformed ICC
profiles. An attacker could use this issue to cause Little CMS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 liblcms2-2 2.16-2ubuntu0.1 liblcms2-utils 2.16-2ubuntu0.1 Ubuntu 24.04 LTS liblcms2-2 2.14-2ubuntu0.1 liblcms2-utils 2.14-2ubuntu0.1 Ubuntu 22.04 LTS liblcms2-2 2.12~rc1-2ubuntu0.1 liblcms2-utils 2.12~rc1-2ubuntu0.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8209-1
CVE-2026-41254
Get the latest Linux and open source security news straight to your inbox.