Bug 2547950 (CVE-2026-44034) - CVE-2026-44034 dcmtk: dcmtk: Information disclosure via crafted RLE DICOM file
Summary: CVE-2026-44034 dcmtk: dcmtk: Information disclosure via crafted RLE DICOM file
Keywords:
Status: NEW
Alias: CVE-2026-44034
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2548023 2548025
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 13:05 UTC by OSIDB Bzimport
Modified: 2026-10-08 15:39 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 13:05:11 UTC
A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d.


Note You need to log in before you can comment on or make changes to this bug.