CVE-2026-97059

NameCVE-2026-97059
DescriptionDCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dcmtk (PTS)bookworm3.6.7-9~deb12u4vulnerable
trixie3.6.9-5+deb13u3vulnerable
forky, sid3.7.0+really3.7.0-7vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dcmtksource(unstable)(unfixed)

Notes

https://support.dcmtk.org/redmine/issues/1281
Fixed by: https://github.com/DCMTK/dcmtk/commit/18379d5b8d234977cc30644e9e70d76d89c87285
Fixed by: https://github.com/DCMTK/dcmtk/commit/c33790827a192a598d20463af701a8b819f46ec1

Search for package or bug name: Reporting problems