DFIR Radar[verified]@DFIR_RadarDisclosure
The tweet announces CVE-2026-41254, detailing an integer overflow/heap underflow in lcms2 that causes segfaults and possible information disclosure in PDF processors.
WindowsForum[verified]@windowsforumDisclosure
The tweet announces CVE-2026-41254, an integer‑overflow issue in lcms2 affecting image tools, offering basic technical details without any PoC, exploit code, or patch information.
Open Source Security mailing list@oss_securityDisclosure
The post details CVE-2026-41254 as an integer overflow in the lcms2 library triggered by a small PDF, affecting numerous Ubuntu 24.04 PDF consumers, but it provides no PoC, exploitation, or patch information.
Open Source Security mailing list@oss_securityPatch
Both integer‑overflow bugs in lcms2 were addressed in a new upstream release; no active exploitation or PoC is mentioned.
CVE@CVEnewDisclosure
The post describes an integer overflow in Little CMS (lcms2) up to version 2.18, providing technical details about the defect but offering no PoC, exploit, patch, or evidence of active attacks.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly disclosed integer overflow vulnerability (CVE‑2026‑41254) in Little CMS lcms2 ≤ 2.18 affects the CubeSize calculation.