A heap-based out-of-bounds read in DcmRLECodecDecoder::decodeFrame() in dcmdata/libsrc/dcrleccd.cc of OFFIS DCMTK 3.7.0 allows an attacker to read up to 63 bytes of adjacent heap memory, or cause a crash, via a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64-byte RLE header. The function copies 64 bytes without checking the fragment length, a check that the sibling function decode() already performs. Applications that decode RLE images frame by frame (for example, through DcmPixelData::getUncompressedFrame()) are affected. The dcmdrle command-line tool uses decode() and is not affected. The issue is fixed in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d.
https://support.dcmtk.org/redmine/issues/1213
https://github.com/DCMTK/dcmtk/commit/45469f3c30037e9c7159290e4bb74cd7b3b9ef1d
Published: 2026-10-08
Updated: 2026-10-08
Base Score: 3.6
Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:P
Severity: Low
Base Score: 4.4
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Severity: Medium
Base Score: 4.8
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00107