Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8209-2: Little CMS vulnerability

A vulnerability (CVE-2026-41254, CVSS 4.0) in the Little CMS color management library allows an attacker to cause a denial of service or potentially execute arbitrary code by tricking the library into opening a specially crafted, malformed ICC profile. The NVD states the vulnerability affects littlecms versions up to and including 2.18. The article provides patched package versions for Ubuntu LTS releases but does not specify a general fixed version for Little CMS itself; Ubuntu administrators should apply the provided `liblcms2` package updates via a standard system update.
Read Full Article →

Ubuntu Security Notices USN-8209-2 USN-8209-2: Little CMS vulnerability Publication date 1 June 2026 Overview Little CMS could be made to crash or run programs if it opened a specially crafted ICC profile. Releases 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages lcms2 - Little CMS color management library Details USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could use this issue to cause Little CMS to crash, resulting in a denial of service, or possibly execute arbitrary code. USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that Little CMS incorrectly handled certain malformed ICC profiles. An attacker could use this issue to cause Little CMS to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal liblcms2-2 – 2.9-4ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro . liblcms2-dev – 2.9-4ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro . liblcms2-utils – 2.9-4ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic liblcms2-2 – 2.9-1ubuntu0.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . liblcms2-dev – 2.9-1ubuntu0.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . liblcms2-utils – 2.9-1ubuntu0.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial liblcms2-2 – 2.6-3ubuntu2.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. liblcms2-dev – 2.6-3ubuntu2.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. liblcms2-utils – 2.6-3ubuntu2.1+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. 14.04 LTS trusty liblcms2-2 – 2.5-0ubuntu4.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. liblcms2-dev – 2.5-0ubuntu4.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. liblcms2-utils – 2.5-0ubuntu4.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-41254 CVE-2026-41254 Related notices USN-8209-1 USN-8209-1

Share this article