---
id: CVE-2026-44034
title: >-
  A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in
  dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up
  to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE
  Lossless DICOM…
summary: >-
  A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in
  dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up
  to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE
  Lossless DICOM…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'
cwe:
  - CWE-125
vendor: OFFIS
product: DCMTK
affected:
  - DCMTK 3.7.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:10:00.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44034'
references:
  - url: >-
      https://github.com/DCMTK/dcmtk/commit/45469f3c30037e9c7159290e4bb74cd7b3b9ef1d
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
  - url: 'https://support.dcmtk.org/redmine/issues/1213'
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T14:09:13.036801Z'
ingestedAt: '2026-10-08T13:42:55.144Z'
---

## Overview

A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
