Back to vendor advisories
Microsoft Security Response CenterCVE-2025-29070

A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."

MediumVendor CVSS 5.3 / 10 1 CVE Published Aug 7, 2026 at 12:57 AM UTC

Summary

Mariner

Products covered

  • cbl2 lcms2 2.13.1-2 on CBL-Mariner 2.0

  • cbl2 lcms2 2.13.1-2

  • azl3 lcms2 2.15-1 on Azure Linux 3.0

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Updated by Microsoft Security Response Center

    The vendor changed the advisory after it was first published.

  3. Added to SecurityAlert

    We collected the advisory from the official source.