PatchSiren cyber security CVE debrief
CVE-2026-44038 OFFIS CVE debrief
A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. This issue can lead to potential crashes or incorrect pixel data decoding, emphasizing the need for defenders to verify and update DCMTK installations.
- Vendor
- OFFIS
- Product
- DCMTK
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems that use DCMTK for DICOM image processing should assess their exposure and prioritize updating to a fixed version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify DCMTK installations and configurations to ensure strict Huffman table checks are enabled.
Why it matters
CVE-2026-44038 is a medium-severity vulnerability in DCMTK's JPEG Huffman decoding, potentially leading to crashes or incorrect pixel data decoding. Defenders should verify and update DCMTK installations, especially in systems handling DICOM images.
- Potential crashes or service disruptions due to out-of-bounds memory reads.
- Incorrect decoding of pixel data, leading to potential diagnostic errors.
- Verification of DCMTK installations and configurations to ensure strict Huffman table checks are enabled.
Technical summary
The vulnerability exists in the Huffman decoder of the IJG JPEG libraries bundled with OFFIS DCMTK 3.7.0. An attacker can exploit this by providing a DICOM file with a crafted JPEG stream, leading to a potential crash or incorrect pixel data decoding. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5, emphasizing the need for defenders to prioritize verifying and updating DCMTK installations to prevent potential crashes or incorrect pixel data decoding. DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK can mitigate the issue.
Defensive priority
Defenders should prioritize verifying and updating DCMTK installations to prevent potential crashes or incorrect pixel data decoding.
Recommended defensive actions
- Verify DCMTK installations for version 3.7.0 and assess exposure to crafted DICOM files.
- Update DCMTK to a version that includes the fix commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.
- Implement strict Huffman table checks by building DCMTK with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK enabled.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The issue is confirmed in DCMTK 3.7.0 and fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. The CVE Program and NVD provide official records of the vulnerability. Evidence is based on source item details and official CVE metadata. Defenders should verify DCMTK installations and configurations to ensure strict Huffman table checks are enabled.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44038 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44038
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44038 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44038
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Global buffer out-of-bounds read in DCMTK JPEG Huffman decoding
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/44xxx/CVE-2026-44038.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.dcmtk.org/redmine/issues/1221
Supplemental source - issue-tracking, vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/DCMTK/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.