CVE-2026-5442

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.
References
Link Resource
https://kb.cert.org/vuls/id/536588 Third Party Advisory VDB Entry
https://www.machinespirits.de/ Not Applicable
https://www.orthanc-server.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-09 15:16

Updated : 2026-06-17 10:59


NVD link : CVE-2026-5442

Mitre link : CVE-2026-5442

CVE.ORG link : CVE-2026-5442


JSON object : View

Products Affected

orthanc-server

  • orthanc
CWE
CWE-787

Out-of-bounds Write