Ubuntu 26.04 LTS Vulnerability in Little CMS

Ubuntu 26.04 LTS Vulnerability in Little CMS

First seen 7 May 2026, 21:08 UTC UbuntuLinuxsecurity 81% similarity 45.9

Article Content

Browse articles
ThreatCluster

A vulnerability in the Little CMS color management library affects Ubuntu 26.04 LTS and 25.10. Discovered on April 30, 2026, the flaw allows attackers to crash the library by using specially crafted ICC profiles, leading to a denial of service. The issue is tracked as CVE-2026-42798. Users are advised to update to the patched versions of liblcms2-2 to mitigate the risk. The vulnerability does not appear to have been actively exploited at this time. Standard system updates will address the issue for affected systems. Ubuntu Pro offers extended security coverage for users with multiple machines. The vulnerability highlights the importance of regular updates to maintain system security.

Key Points: • A vulnerability in Little CMS affects Ubuntu 26.04 LTS and 25.10. • The flaw allows denial of service via specially crafted ICC profiles. • Users should update to the latest liblcms2-2 packages to mitigate risks.

ThreatCluster AI

Timeline

2026-04-30
CVE-2026-42798 published
A vulnerability in Little CMS was disclosed, allowing potential denial of service through malformed ICC profiles.
Linuxsecurity
2026-05-07
Security advisory issued
Ubuntu released USN-8250-1, detailing the vulnerability and providing patch information for affected systems.
Ubuntu

Community

Browse all →

Tracked Entities in This Story