A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers. | |
| Title | Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode) | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-09T14:43:15.227Z
Reserved: 2026-04-02T19:23:06.757Z
Link: CVE-2026-5443
No data.
Status : Received
Published: 2026-04-09T15:16:16.653
Modified: 2026-04-09T15:16:16.653
Link: CVE-2026-5443
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.