No advisories yet.
Solution
Update to a DCMTK version that contains commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. | |
| Title | Global buffer out-of-bounds read in DCMTK JPEG Huffman decoding | |
| First Time appeared |
Offis
Offis dcmtk |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Offis
Offis dcmtk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:08:19.615Z
Reserved: 2026-05-05T02:49:00.667Z
Link: CVE-2026-44038
Updated: 2026-10-08T14:08:15.791Z
Status : Received
Published: 2026-10-08T13:17:17.963
Modified: 2026-10-08T15:17:54.220
Link: CVE-2026-44038
No data.
OpenCVE Enrichment
Updated: 2026-10-08T14:45:17Z