PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44038 OFFIS CVE debrief

A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. This issue can lead to potential crashes or incorrect pixel data decoding, emphasizing the need for defenders to verify and update DCMTK installations.

Vendor
OFFIS
Product
DCMTK
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems that use DCMTK for DICOM image processing should assess their exposure and prioritize updating to a fixed version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify DCMTK installations and configurations to ensure strict Huffman table checks are enabled.

Why it matters

CVE-2026-44038 is a medium-severity vulnerability in DCMTK's JPEG Huffman decoding, potentially leading to crashes or incorrect pixel data decoding. Defenders should verify and update DCMTK installations, especially in systems handling DICOM images.

  • Potential crashes or service disruptions due to out-of-bounds memory reads.
  • Incorrect decoding of pixel data, leading to potential diagnostic errors.
  • Verification of DCMTK installations and configurations to ensure strict Huffman table checks are enabled.

Technical summary

The vulnerability exists in the Huffman decoder of the IJG JPEG libraries bundled with OFFIS DCMTK 3.7.0. An attacker can exploit this by providing a DICOM file with a crafted JPEG stream, leading to a potential crash or incorrect pixel data decoding. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5, emphasizing the need for defenders to prioritize verifying and updating DCMTK installations to prevent potential crashes or incorrect pixel data decoding. DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK can mitigate the issue.

Defensive priority

Defenders should prioritize verifying and updating DCMTK installations to prevent potential crashes or incorrect pixel data decoding.

Recommended defensive actions

  • Verify DCMTK installations for version 3.7.0 and assess exposure to crafted DICOM files.
  • Update DCMTK to a version that includes the fix commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.
  • Implement strict Huffman table checks by building DCMTK with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK enabled.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The issue is confirmed in DCMTK 3.7.0 and fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5. The CVE Program and NVD provide official records of the vulnerability. Evidence is based on source item details and official CVE metadata. Defenders should verify DCMTK installations and configurations to ensure strict Huffman table checks are enabled.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44038 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44038

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44038 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44038

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Global buffer out-of-bounds read in DCMTK JPEG Huffman decoding

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/44xxx/CVE-2026-44038.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://support.dcmtk.org/redmine/issues/1221

    Supplemental source - issue-tracking, vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/DCMTK/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5

    Supplemental source - patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.