CVE-2026-44034
Received Received - Intake

Heap Out-of-Bounds Read in DCMTK

Vulnerability report for CVE-2026-44034, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OFFIS DCMTK 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based out-of-bounds read vulnerability in the DCMTK library's RLE frame decoding function. It occurs when processing a maliciously crafted RLE Lossless DICOM file with a pixel data fragment shorter than the required 64-byte RLE header. The function attempts to copy 64 bytes without validating the fragment length, potentially reading up to 63 adjacent heap memory bytes or causing a crash.

Detection Guidance

To detect this vulnerability, inspect DICOM files processed by DCMTK 3.7.0 for RLE Lossless pixel data fragments shorter than 64 bytes. Use DCMTK tools like dcmdump to analyze DICOM files for malformed RLE headers. Check if applications using DcmPixelData::getUncompressedFrame() crash when processing such files.

Impact Analysis

An attacker could exploit this to read sensitive memory data or crash the application processing the malicious DICOM file. This may lead to information disclosure or denial-of-service conditions, particularly in applications that decode RLE images frame by frame using affected functions.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive data through heap memory reads. If exploited, it may allow unauthorized access to adjacent memory containing personal or health information during DICOM file processing, violating data confidentiality requirements.

Mitigation Strategies

Upgrade DCMTK to a version containing commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d. Avoid processing untrusted RLE Lossless DICOM files until patched. If immediate upgrade is not possible, disable RLE decoding in affected applications or filter incoming DICOM files for valid RLE headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44034. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart