{"id":"UBUNTU-CVE-2026-42798","details":"Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.","modified":"2026-05-20T16:13:00.373455955Z","published":"2026-05-05T00:00:00Z","related":["USN-8250-1"],"upstream":["CVE-2026-42798"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42798"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-42798"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8250-1"}],"affected":[{"package":{"name":"lcms2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/lcms2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.16-2ubuntu0.2"}]}],"versions":["2.16-2","2.16-2ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblcms2-2","binary_version":"2.16-2ubuntu0.2"},{"binary_name":"liblcms2-utils","binary_version":"2.16-2ubuntu0.2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42798.json"}},{"package":{"name":"lcms2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/lcms2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.17-1ubuntu0.2"}]}],"versions":["2.16-2","2.17-1","2.17-1ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblcms2-2","binary_version":"2.17-1ubuntu0.2"},{"binary_version":"2.17-1ubuntu0.2","binary_name":"liblcms2-utils"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-42798.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}