Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves two vulnerabilities can now be installed.. # Security update for lcms2 Announcement ID: SUSE-SU-2026:22506-1 Release Date: 2026-07-01T12:17:04Z Rating: moderate References: * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42798 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42798 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for lcms2 fixes the following issues * CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994). * CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * liblcms2-devel-2.16-160000.4.1 * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 *SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * liblcms2-devel-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html * https://bugzilla.suse.com/show_bug.cgi?id=1263703 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 . Two vulnerabilities in lcms2 are addressed in this SUSE security update with moderate severity, urging immediate installation.. lcms2 security update, SUSE lcms2 patch, moderate severity fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for lcms2 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21202-1 Rating: moderate References: * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42798 ( SUSE ): 4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for lcms2 fixes the following issues - CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994). - CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1125=1 Package List: - openSUSE Leap 16.0: lcms2-2.16-160000.4.1 liblcms2-2-2.16-160000.4.1 liblcms2-devel-2.16-160000.4.1 liblcms2-doc-2.16-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html . Update for openSUSE fixes two vulnerabilities in lcms2 and introduces bug fixes. Immediate patching recommended.. openSUSE lcms2 security fix integer overflow patch. . Severity: moderate. LinuxSecurity.com Team
Security update. Publication date: 16 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0214.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-41254 Description: Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. (CVE-2026-41254) References: - https://bugs.mageia.org/show_bug.cgi?id=35424 - https://www.openwall.com/lists/oss-security/2026/04/17/16 - https://www.openwall.com/lists/oss-security/2026/04/18/1 - https://abhinavagarwal07.github.io/posts/lcms2-cubesize-overflow/ - https://lists.debian.org/debian-security-announce/2026/msg00173.html - https://www.cve.org/CVERecord?id=CVE-2026-41254 SRPMS: - 9/core/lcms2-2.15-2.1.mga9 . Mageia 9 security advisory for lcms2 details critical integer overflow that needs immediate attention.. Mageia 9, security update, integer overflow, lcms2, threat advisory. . Severity: Critical. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for lcms2 Announcement ID: SUSE-SU-2026:22070-1 Release Date: 2026-06-05T14:42:55Z Rating: moderate References: * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42798 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42798 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for lcms2 fixes the following issues * CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994). * CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-566=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * liblcms2-2-debuginfo-2.16-slfo.1.1_2.1 * lcms2-debugsource-2.16-slfo.1.1_2.1 * liblcms2-2-2.16-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html * https://bugzilla.suse.com/show_bug.cgi?id=1263703 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 . Install the latest SUSE update for lcms2 addressing two integer overflow issues and improve system stability.. SUSE Linux Update, lcms2 Security Fix, VulnerabilityManagement. . Severity: moderate. LinuxSecurity.com Team
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.. ========================================================================== Ubuntu Security Notice USN-8209-2 June 01, 2026 lcms2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile. Software Description: - lcms2: Little CMS color management library Details: USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could use this issue to cause Little CMS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS liblcms2-2 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro liblcms2-dev 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro liblcms2-utils 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS liblcms2-2 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro liblcms2-dev 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro liblcms2-utils 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS liblcms2-2 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro liblcms2-dev 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro liblcms2-utils 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS liblcms2-2 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro liblcms2-dev 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro liblcms2-utils 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8209-2 https://ubuntu.com/security/notices/USN-8209-1 CVE-2026-41254 . Little CMS on Ubuntu systems is vulnerable to crash or remote code execution. Update packages to mitigate this risk.. Little CMS Ubuntu updates denial of service. . Severity: Critical. LinuxSecurity.com Team
Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile.. ========================================================================== Ubuntu Security Notice USN-8209-2 June 01, 2026 lcms2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile. Software Description: - lcms2: Little CMS color management library Details: USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could use this issue to cause Little CMS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS liblcms2-2 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro liblcms2-dev 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro liblcms2-utils 2.9-4ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS liblcms2-2 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro liblcms2-dev 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro liblcms2-utils 2.9-1ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS liblcms2-2 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro liblcms2-dev 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro liblcms2-utils 2.6-3ubuntu2.1+esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS liblcms2-2 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro liblcms2-dev 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro liblcms2-utils 2.5-0ubuntu4.2+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8209-2 https://ubuntu.com/security/notices/USN-8209-1 CVE-2026-41254 . Ensure your Ubuntu system is safe by applying the latest updates for Little CMS's denial of service vulnerability from advisory USN-8209-2.. Linux updates, Ubuntu security, lcms2 patch, Little CMS advisory, denial of service. . Severity: high. LinuxSecurity.com Team
Two integer overflows were discovered in the LittleCMS 2 colour management library. For the oldstable distribution (bookworm), this problem has been fixed in version 2.14-2+deb12u1. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6262-1
Little CMS could be made to crash if it opened a specially crafted ICC profile.. ========================================================================== Ubuntu Security Notice USN-8250-1 May 07, 2026 lcms2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Little CMS could be made to crash if it opened a specially crafted ICC profile. Software Description: - lcms2: Little CMS color management library Details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could possibly use this issue to cause Little CMS to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS liblcms2-2 2.17-1ubuntu0.2 Ubuntu 25.10 liblcms2-2 2.16-2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8250-1 CVE-2026-42798 Package Information: https://launchpad.net/ubuntu/+source/lcms2/2.17-1ubuntu0.2 https://launchpad.net/ubuntu/+source/lcms2/2.16-2ubuntu0.2 . Little CMS crash vulnerability in Ubuntu 26.04 and 25.10 requires urgent updates to prevent denial of service.. Ubuntu lcms2 Denial of Service ICC profile crash. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.