Global Out-of-Bounds Read in OFFIS DCMTK JPEG Libraries
CVE-2026-44038

4.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-44038?

A global out-of-bounds read vulnerability exists in the Huffman decoder of the bundled IJG JPEG libraries within OFFIS DCMTK 3.7.0. This flaw allows attackers to read memory outside of defined tables, resulting in incorrect pixel data or application crashes. The issue arises when processing crafted DICOM files containing specially designed JPEG streams with Huffman tables that have a difference category exceeding 15. By default, the necessary range-checking of Huffman symbol values is not enabled, meaning that applications utilizing dcmtjpeg for JPEG DICOM image decompression are at risk unless protective measures are taken.

Affected Version(s)

DCMTK 3.7.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.