CVE-2026-41254Disclosure(littlecms / little_cms)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch littlecms little_cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-696CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • little_cms

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-18); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
little_cms

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-18: 3Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-30: 104-1804-1904-2104-30
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-183
Disclosure3
2026-04-191
Disclosure1
2026-04-211
Disclosure1
2026-04-301
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41254: lcms2 <= 2.18 CubeSize() integer overflow https://www.openwall.com/lists/oss-security/2026/04/17/16 992-byte PDF crashes Ubuntu 24.04 consumers: evince-thumbnailer, Poppler (pdftoppm / pdftocairo / pdfimages), the cups-filters PDF-to-raster print filter, Okular, GIMP's PDF plugin, OpenJDK 21 ...

    Post summary

    The post details CVE-2026-41254 as an integer overflow in the lcms2 library triggered by a small PDF, affecting numerous Ubuntu 24.04 PDF consumers, but it provides no PoC, exploitation, or patch information.

    121811.1K
    4.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-41254 assigned for lcms2 ≤2.18 integer overflow causing segfaults in Ubuntu 24.04 Poppler, evince-thumbnailer, OpenJDK, and other PDF processors. 992-byte crafted PDF triggers heap buffer underflow with potential info disclosure. #DFIR_Radar https://t.co/cexvCgOvwe

    Post summary

    The tweet announces CVE-2026-41254, detailing an integer overflow/heap underflow in lcms2 that causes segfaults and possible information disclosure in PDF processors.

    10010186
    1.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Additionally to "CVE-2026-41254: lcms2 <= 2.18 CubeSize() integer overflow", there's now "ParseCube integer overflow in LUT allocation", which was similarly fixed without CVE (pending now). Upstream made a release with both fixes. https://www.openwall.com/lists/oss-security/2026/04/30/8

    Post summary

    Both integer‑overflow bugs in lcms2 were addressed in a new upstream release; no active exploitation or PoC is mentioned.

    00010145
    4.5K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 Another “oops, we checked after the multiplication” CVE. Integer overflows in lcms2 mean dodgy color files can turn image tools into risk multipliers. Fix order, Microsoft-style! https://windowsforum.com/threads/cve-2026-41254-integer-overflow-in-little-cms-lcms2-cubesize.414495/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #IntegerOverflow #SecurityUpdateGuide #Cve202641254 #LittleCms https://t.co/iwsJ1QqKsa

    Post summary

    The tweet announces CVE-2026-41254, an integer‑overflow issue in lcms2 affecting image tools, offering basic technical details without any PoC, exploit code, or patch information.

    0000029
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41254 Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. https://www.cve.org/CVERecord?id=CVE-2026-41254

    Post summary

    The post describes an integer overflow in Little CMS (lcms2) up to version 2.18, providing technical details about the defect but offering no PoC, exploit, patch, or evidence of active attacks.

    0000052
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41254 Integer Overflow in Little CMS lcms2 Through 2.18 CubeSize Calculation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41254

    Post summary

    A newly disclosed integer overflow vulnerability (CVE‑2026‑41254) in Little CMS lcms2 ≤ 2.18 affects the CubeSize calculation.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applittlecmslittle_cms---

Explore more