---
id: CVE-2025-11266
title: >-
  An out-of-bounds write vulnerability exists in the Grassroots DICOM library
  (GDCM)
summary: >-
  An out-of-bounds write vulnerability exists in the Grassroots DICOM library
  (GDCM). The issue is triggered during parsing of a malformed DICOM file
  containing encapsulated PixelData fragments (compressed image data stored as
  multiple fra…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'
cwe:
  - CWE-787
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11266'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsma-25-345-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://github.com/malaterre/GDCM/releases/tag/v3.2.2'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-345-01'
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://github.com/malaterre/GDCM/commit/5829c95c8ac3afa9a3a3413675e948959c28a789
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00146
epssPercentile: 0.03282
ingestedAt: '2026-10-07T20:46:46.910Z'
---

## Overview

An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an out-of-bounds memory access due to unsigned integer underflow in buffer indexing. It is exploitable via file input, simply opening a crafted malicious DICOM file is sufficient to trigger the crash, resulting in a denial-of-service condition.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
