-------------------------------------------------------------------------
Debian LTS Advisory DLA-4652-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emmanuel Arias
June 26, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------
Package : gdcm
Version : 3.0.8-2+deb11u1
CVE ID : CVE-2024-22373 CVE-2024-22391 CVE-2024-25569 CVE-2025-11266
CVE-2025-48429 CVE-2025-52582 CVE-2025-53618 CVE-2025-53619
CVE-2026-3650
Debian Bug : 1070387 1122862 1123576 1123587 1123589 1132042
Multiple vulnerabilities were discovered in gdcm, a C++ library for working
with DICOM medical files:
CVE-2024-22373
An out-of-bounds write vulnerability exists in the
JPEG2000Codec::DecodeByStreamsCommon functionality. A specially crafted
DICOM file can lead to a heap buffer overflow. An attacker can provide a
malicious file to trigger this vulnerability.
CVE-2024-22391
A heap-based buffer overflow vulnerability exists in the
LookupTable::SetLUT functionality. A specially crafted malformed file can
lead to memory corruption. An attacker can provide a malicious file to
trigger this vulnerability.
CVE-2024-25569
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes
functionality. A specially crafted DICOM file can lead to an out-of-bounds
read. An attacker can provide a malicious file to trigger this
vulnerability.
CVE-2025-11266
An out-of-bounds write vulnerability exists in the parsing of a malformed
DICOM file containing encapsulated PixelData fragments (compressed image
data stored as multiple fragments). This vulnerability leads to a
segmentation fault caused by an out-of-bounds memory access due to an
unsigned integer underflow in buffer indexing. It is exploitable via file
input: simply opening a crafted malicious DICOM file is sufficient to
trigger the crash, resulting in a denial-of-service condition.
CVE-2025-48429
An out-of-bounds read vulnerability exists in the
RLECodec::DecodeByStreams functionality. A specially crafted DICOM file
can lead to leaking heap data. An attacker can provide a malicious file to
trigger this vulnerability.
CVE-2025-52582
An out-of-bounds read vulnerability exists in the
Overlay::GrabOverlayFromPixelData functionality. A specially crafted DICOM
file can lead to an information leak. An attacker can provide a malicious
file to trigger this vulnerability.
CVE-2025-53618
An out-of-bounds read vulnerability exists in the
JPEGBITSCodec::InternalCode functionality. A specially crafted DICOM file
can lead to an information leak. An attacker can provide a malicious file
to trigger this vulnerability. The function grayscale_convert is called
based on the value of the malicious DICOM file specifying the intended
interpretation of the image pixel data.
CVE-2025-53619
An out-of-bounds read vulnerability exists in the
JPEGBITSCodec::InternalCode functionality. A specially crafted DICOM file
can lead to an information leak. An attacker can provide a malicious file
to trigger this vulnerability. The function null_convert is called based
on the value of the malicious DICOM file specifying the intended
interpretation of the image pixel data.
CVE-2026-3650
A memory leak exists when parsing malformed DICOM files with non-standard
VR types in file meta information. The vulnerability leads to vast memory
allocations and resource depletion, triggering a denial-of-service
condition. A maliciously crafted file can fill the heap in a single read
operation without properly releasing it.
For Debian 11 bullseye, these problems have been fixed in version
3.0.8-2+deb11u1.
We recommend that you upgrade your gdcm packages.
For the detailed security status of gdcm please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/gdcm
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature