Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41254

30
FAUCET Score

CVE-2026-41254 is an integer overflow vulnerability in Little CMS (lcms2) version 2.18 and earlier, located in the CubeSize function within cmslut.c file. The flaw occurs because an overflow check is performed after multiplication rather than before, allowing an attacker to trigger the condition. This vulnerability affects any software that utilizes the vulnerable lcms2 library for color management operations. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction. The attack is straightforward to execute with low complexity, and while it does not compromise confidentiality or integrity, it can cause availability denial through a denial-of-service condition. The FAUCET Risk Score of 48.0/100 indicates moderate concern within the threat landscape. While the vulnerability is actively tracked on security hot lists, current exploitation evidence is limited, with an EPSS score of 0.000380 suggesting minimal real-world exploitation activity to date. No public exploit code has been widely distributed, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Organizations using Little CMS should apply patches when available, prioritizing systems processing untrusted image or color profile data.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 2.18CPE match
cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:*
<= 2.18CPE matchmatch criteria
cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.4
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
29.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 10th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 lcms2 2.15-1 on Azure Linux 3.0Fixed in: 2.15-2
microsoftpatch availablevia msrc
Product: 21287-17084Fixed in: 2.15-2
microsoftpatch availablevia msrc
Product: 21226-17084Fixed in: 2.15-2
microsoftpatch availablevia msrc
Product: azl3 lcms2 2.15-2 on Azure Linux 3.0Fixed in: 2.15-2
ubuntupatch availablevia ubuntu_usn
Product: lcms2 (focal)Fixed in: 2.9-4ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: lcms2 (trusty)Fixed in: 2.5-0ubuntu4.2+esm1
ubuntupatch availablevia ubuntu_usn
Product: lcms2 (xenial)Fixed in: 2.6-3ubuntu2.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: lcms2 (bionic)Fixed in: 2.9-1ubuntu0.1+esm1

Vendor Advisories (2)

ubuntuUSN-8209-2

Little CMS vulnerability

Jun 1, 2026
microsoft2026-Apr/CVE-2026-41254Moderate

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Apr 14, 2026

References

lists.debian.org / debian-lts-announce/2026/05/msg00014.html
abhinavagarwal07.github.io / posts/lcms2-cubesize-overflow
ExploitThird Party Advisory
github.com / mm2/Little-CMS/commit/da6110b1d14abc394633a388209abd5ebedd7ab0
Patch
github.com / mm2/Little-CMS/commit/e0641b1828d0a1af5ecb1b11fe22f24fceefd4bc
Patch
github.com / mm2/Little-CMS/security/advisories/GHSA-4xp6-rcgg-m9qq
Broken Link
openwall.com / lists/oss-security/2026/04/17/16
Mailing ListThird Party Advisory