Description
Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability lies in the DcmDicomDir::moveRecordToTree function in DCMTK 3.7.0, where recursive processing of deeply chained directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute can cause uncontrolled recursion. The resulting stack exhaustion leads to a process crash, delivering a denial‑of‑service condition. This flaw is a classic example of uncontrolled recursion (CWE‑674) and directly compromises application availability.

Affected Systems

The exploit targets OFFIS DCMTK 3.7.0 and any application built on that library, such as dcmgpdir and other media viewers that accept DICOMDIR files. The vulnerability exists only in this specific release; later tagged releases are not yet available, so the fix must be obtained from the commit or current master.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. With no EPSS data, the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA KEV. Attackers can trigger the failure by supplying a specially crafted DICOMDIR file with an excessively deep record chain, which can be delivered locally or remotely if a vulnerable application processes files from untrusted sources. Successful exploitation results in stack exhaustion and a full application crash, preventing further processing of the file and potentially affecting other users or services running on the same host.

Generated by OpenCVE AI on October 8, 2026 at 14:25 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Apply the commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f or upgrade to a newer DCMTK build from master that includes the fix.
  • If upgrading is not immediately possible, isolate and restrict the use of DCMTK‑based applications to prevent processing of untrusted DICOMDIR files, or enforce a safe depth limit in the application if configurable.
  • Monitor application logs for stack exhaustion or crashes and be prepared to restart services.

Generated by OpenCVE AI on October 8, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.
Title Uncontrolled recursion in DCMTK DICOMDIR parsing allows denial of service
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-674
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:09:00.382Z

Reserved: 2026-05-05T02:49:00.667Z

Link: CVE-2026-44035

cve-icon Vulnrichment

Updated: 2026-10-08T14:08:55.352Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.497

Modified: 2026-10-08T15:17:53.967

Link: CVE-2026-44035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:15:11Z

Weaknesses