CVE-2025-29070: A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."

Overview

Severity
Medium (CVSS 5.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploit Status
Not Exploited
Patch Tuesday
2025-Apr
Released
2026-08-07
Last Updated
2026-08-12
EPSS Score
0.94% (percentile: 58.8%)

Affected Products (3)

Other

  • 21225-21692
  • 21225
  • 21226-17084

Revision History

  • 2026-08-07: Information published.
  • 2026-08-12: Information published.