Global Out-of-Bounds Read in OFFIS DCMTK JPEG Libraries
CVE-2026-44038
4.8MEDIUM
What is CVE-2026-44038?
A global out-of-bounds read vulnerability exists in the Huffman decoder of the bundled IJG JPEG libraries within OFFIS DCMTK 3.7.0. This flaw allows attackers to read memory outside of defined tables, resulting in incorrect pixel data or application crashes. The issue arises when processing crafted DICOM files containing specially designed JPEG streams with Huffman tables that have a difference category exceeding 15. By default, the necessary range-checking of Huffman symbol values is not enabled, meaning that applications utilizing dcmtjpeg for JPEG DICOM image decompression are at risk unless protective measures are taken.
Affected Version(s)
DCMTK 3.7.0
