PatchSiren cyber security CVE debrief
CVE-2025-11266 Grassroots CVE debrief
CVE-2025-11266 is a medium-severity memory-safety flaw in Grassroots DICOM (GDCM) that can be triggered by opening a crafted DICOM file. The advisory says malformed encapsulated PixelData fragments can cause an unsigned integer underflow in buffer indexing, leading to an out-of-bounds memory access and segmentation fault. In practical terms, this is a denial-of-service issue for software that parses untrusted DICOM content.
- Vendor
- Grassroots
- Product
- SimpleITK
- CVSS
- MEDIUM 6.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-11
- Original CVE updated
- 2025-12-11
- Advisory published
- 2025-12-11
- Advisory updated
- 2025-12-11
Who should care
Teams running software that embeds or depends on GDCM, including SimpleITK and medInria deployments, should care most. This is especially relevant for imaging workflows that accept DICOM files from outside the organization or from less-trusted sources.
Technical summary
The source advisory describes an out-of-bounds write in the Grassroots DICOM library during parsing of malformed DICOM files containing encapsulated PixelData fragments. The failure mode is an unsigned integer underflow in buffer indexing, which can produce an out-of-bounds memory access and segmentation fault. The issue is exploitable through file input alone; simply opening a crafted malicious DICOM file is sufficient to trigger the crash. The supplied CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H, and the score is 6.6 (Medium).
Defensive priority
Medium. The issue is limited to file-triggered denial of service in the supplied advisory, but it affects parsing of untrusted medical imaging content and can be triggered by opening a malicious file.
Recommended defensive actions
- Update Grassroots DICOM (GDCM) to v3.2.2 or later, as recommended by the maintainer.
- Apply the released fixes for downstream products that embed or package the library, including SimpleITK and medInria.
- Treat DICOM files from untrusted sources as potentially malicious until patched versions are deployed.
- Prioritize remediation in any workflow where users open externally supplied imaging files.
Evidence notes
The supplied CISA CSAF advisory (ICSMA-25-345-01) states that the flaw is an out-of-bounds write in GDCM triggered while parsing malformed DICOM files with encapsulated PixelData fragments, and that opening a crafted file can cause a segmentation fault and denial of service. The advisory recommends updating GDCM to v3.2.2 or later and notes that SimpleITK and medInria have released fixes. The CVE and source advisory were both published on 2025-12-11 in the supplied data. No CISA KEV entry is present in the supplied enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-11266 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-11266
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-11266 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-11266
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-345-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-345-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.