CVE-2026-44038
Received Received - Intake

Global Out-of-Bounds Read in DCMTK JPEG Decoder

Vulnerability report for CVE-2026-44038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OFFIS DCMTK 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read flaw in the Huffman decoder of DCMTK's bundled IJG JPEG libraries. It occurs when a crafted DICOM file contains a JPEG stream with a Huffman table defining a difference category above 15. This causes the code to access memory outside valid arrays like extend_test[] and extend_offset[], leading to incorrect pixel data or crashes. The issue arises because DCMTK does not check Huffman symbol values by default unless built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK.

Detection Guidance

Detecting this vulnerability requires checking for DCMTK versions vulnerable to CVE-2026-44038. Inspect installed DCMTK packages using commands like 'dpkg -l | grep dcmtk' on Debian/Ubuntu or 'rpm -qa | grep dcmtk' on RHEL-based systems. Verify if the version is below the patched commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.

Impact Analysis

If you use applications that decompress JPEG DICOM images with DCMTK, an attacker could exploit this flaw by providing a maliciously crafted DICOM file. This may result in application crashes, incorrect image data, or potential memory corruption. The impact is limited to systems processing such files, particularly those using dcmdjpeg or similar tools.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized memory access through crafted DICOM files. If exploited, it may lead to data breaches or corruption of sensitive medical imaging data, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Immediately update DCMTK to a version containing the fix in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. If updating is not possible, disable JPEG DICOM image processing in affected applications or restrict access to systems using vulnerable DCMTK versions until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart