Description
A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.
Published: 2026-10-08
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Possible information disclosure and crash due to out‑of‑bounds read
Action: Patch
AI Analysis

Impact

A global buffer overread occurs in the Huffman decoder of the bundled IJG JPEG libraries used by OFFIS DCMTK 3.7.0. The decoder fails to guard against Huffman symbols that specify a difference category above 15, allowing reads beyond the extend_test[] and extend_offset[] tables. The resulting memory leak can reveal sensitive data, corrupt pixel data, or trigger a crash. The defect remains unprotected unless DCMTK is compiled with a strict Huffman table check, which is disabled by default.

Affected Systems

Applications based on OFFIS DCMTK version 3.7.0, including the dcmdjpeg tool and any software that decompresses JPEG DICOM images with this library, are affected. Systems building DCMTK without enabling the strict Huffman table check are also vulnerable. No other DCMTK releases contain the fix as of the publication date.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate risk level. No EPSS score was reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires an attacker to supply a malicious DICOM file containing a crafted JPEG stream with an oversized Huffman table. Therefore the attack vector is inferred to be local or network file‑processing, depending on how the affected software receives files. There is currently no evidence of active exploitation, but the moderate score and potential memory disclosure suggest that remediation should not be delayed.

Generated by OpenCVE AI on October 8, 2026 at 14:38 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Update DCMTK to a version that includes commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5 or apply the commit manually
  • If immediate patching is not feasible, rebuild DCMTK with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK enabled to enforce range checks on Huffman tables
  • Ensure that any application using dcmdjpeg or similar decompression utilities validates incoming DICOM files or restricts their usage to trusted sources

Generated by OpenCVE AI on October 8, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.
Title Global buffer out-of-bounds read in DCMTK JPEG Huffman decoding
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-125
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:08:19.615Z

Reserved: 2026-05-05T02:49:00.667Z

Link: CVE-2026-44038

cve-icon Vulnrichment

Updated: 2026-10-08T14:08:15.791Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.963

Modified: 2026-10-08T15:17:54.220

Link: CVE-2026-44038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:45:17Z

Weaknesses