CVE-2026-42798
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-42798 is an integer overflow vulnerability in the ParseCube function within cmscgats.c of Little CMS (lcms2), affecting versions 2.16 through 2.18 (fixed in 2.19). The flaw was reported by researcher Abhinav Agarwal and disclosed publicly on April 30, 2026, following upstream's release of lcms2 2.19 on April 24, 2026. It carries a CVSS v3.1 base score of 4.0 (Medium) (Github Advisory, oss-security).

Technical details

The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound). In ParseCube within cmscgats.c, the LUT node count is computed as lut_size * lut_size * lut_size without first validating that lut_size is within a safe range, allowing an oversized value to cause an integer overflow and result in an undersized heap allocation. The fix introduced in commit 6a686019 adds a bounds check rejecting any lut_size greater than 65 (the maximum supported by professional LUT tools) before the multiplication occurs. This is a local attack vector requiring high attack complexity, with no privileges required and no user interaction needed (lcms2 commit, Github Advisory).

Impact

Successful exploitation can lead to low-impact information disclosure and denial of service. An attacker with local access who can supply a crafted input to an application using lcms2 may trigger the integer overflow, causing an undersized buffer allocation and subsequent out-of-bounds memory access, potentially crashing the consuming application or leaking limited heap memory contents. Integrity is not impacted (Github Advisory, oss-security).

Exploitability

There is no public proof-of-concept exploit specifically for CVE-2026-42798, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.012–0.017%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 313713) and Qualys (ID 6276485) (Github Advisory, oss-security).

Mitigation and workarounds

Users should upgrade Little CMS (lcms2) to version 2.19 or later, which was released on April 24, 2026, and includes the fix for this vulnerability. The patch adds a bounds check in ParseCube to reject LUT sizes greater than 65 before the integer multiplication occurs. Distributions such as Ubuntu and Debian have issued advisories (Ubuntu USN-8250-1, Debian DSA-6262-1) with updated packages; administrators should apply these distribution-level updates promptly. As a temporary measure, restricting local access to systems running lcms2-dependent applications reduces exposure (lcms2 commit, Github Advisory).

Community reactions

Researcher Abhinav Agarwal disclosed this vulnerability via the oss-security mailing list on April 30, 2026, noting it was an additional finding alongside the higher-severity CVE-2026-41254 (CubeSize integer overflow). Agarwal noted that the upstream GHSA was closed without substantial engagement before a CVE was assigned. The vulnerability received coverage from Linux security advisory aggregators including LinuxSecurity.com for both Ubuntu and Debian package updates (oss-security).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7867HIGH7.8
  • Linux Debian logoLinux Debian
  • udisks2-lsm
NoYesAug 06, 2026
CVE-2026-71554MEDIUM5.3
  • Python logoPython
  • python-h2
NoYesAug 06, 2026
CVE-2026-71439MEDIUM5.3
  • JavaScript logoJavaScript
  • mermaid
NoYesAug 06, 2026
CVE-2026-71498MEDIUM5.1
  • JavaScript logoJavaScript
  • re2
NoYesAug 06, 2026
CVE-2026-71497MEDIUM4.7
  • Java logoJava
  • jsoup
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management