Description
A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published: 2026-06-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow occurs in the vtk-dicom library’s vtkDICOMItem::FindDataElementOrInsert routine when a DICOM data element exceeds the allocated buffer size. The overflow can corrupt heap memory, potentially causing application crashes, data loss, or other instability. No explicit evidence of code execution is provided in the description. This flaw is classified as CWE‑129 and is present in version 9.5.2 of vtk-dicom.

Affected Systems

The affected product is vtk‑dicom from the VTK project. The flaw appears in version 9.5.2 of the library and any build containing the unpatched vtkDICOMItem::FindDataElementOrInsert routine.

Risk and Exploitability

The vulnerability is triggered by processing a specially crafted DICOM file. An attacker who can supply such a file to a running vtk‑dicom instance can exploit the heap overflow, potentially causing memory corruption or application instability. The CVSS score of 8.1 indicates high severity, the EPSS score is below 1% and the issue is not listed in CISA KEV catalog, suggesting low current likelihood of exploitation. Based on the description, it is inferred that the attack vector is local or remote depending on how the vtk‑dicom instance receives input, and the likely path involves feeding a malicious DICOM file into the library via an application that parses DICOM data.

Generated by OpenCVE AI on September 23, 2026 at 17:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest vtk‑dicom release that incorporates a fix for the heap buffer overflow.
  • Restrict DICOM file processing to trusted sources and validate file integrity before feeding to vtk-dicom.
  • Apply network segmentation or firewall rules to limit exposure of applications that use vtk-dicom to external inputs.

Generated by OpenCVE AI on September 23, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Heap-Based Buffer Overflow in vtk-dicom vtkDICOMItem::NewDataElement

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

Fri, 26 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Vtk
Vtk vtk
Vendors & Products Vtk
Vtk vtk

Thu, 25 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Title Heap-Based Buffer Overflow in vtk-dicom vtkDICOMItem::NewDataElement

Thu, 25 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2026-09-23T10:51:51.588Z

Reserved: 2026-02-05T20:01:55.285Z

Link: CVE-2026-22879

cve-icon Vulnrichment

Updated: 2026-06-25T23:29:39.650Z

cve-icon NVD

Status : Deferred

Published: 2026-06-25T22:17:01.193

Modified: 2026-09-23T11:17:10.433

Link: CVE-2026-22879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T17:45:07Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index