PT-2026-31631 · Unknown · Dicom Image Decoder
Published
2026-04-09
·
Updated
2026-04-09
·
CVE-2026-5442
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DICOM image decoder (affected versions not specified)
Description
A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), allowing extremely large dimensions to be processed. This causes an integer overflow during frame size calculation, resulting in out-of-bounds memory access during image decoding.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dicom Image Decoder