{"id":"CVE-2026-44034","title":"A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM…","summary":"A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","cwe":["CWE-125"],"vendor":"OFFIS","product":"DCMTK","affected":["DCMTK 3.7.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:10:00.133","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44034","references":[{"url":"https://github.com/DCMTK/dcmtk/commit/45469f3c30037e9c7159290e4bb74cd7b3b9ef1d","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1213","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T14:09:13.036801Z"},"ingestedAt":"2026-10-08T13:42:55.144Z","slug":"CVE-2026-44034","body":"## Overview\n\nA heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}