{"id":"CVE-2025-11266","summary":"Grassroots DICOM (GDCM) Out-of-bounds Write","details":"An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an out-of-bounds memory access due to unsigned integer underflow in buffer indexing. It is exploitable via file input, simply opening a crafted malicious DICOM file is sufficient to trigger the crash, resulting in a denial-of-service condition.","modified":"2026-08-12T15:13:36.737309Z","published":"2025-12-12T20:48:57.303Z","database_specific":{"cna_assigner":"icscert","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11266.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"2.5.2"},{"last_affected":"4.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsma-25-345-01.json"},{"type":"WEB","url":"https://github.com/malaterre/GDCM/releases/tag/v3.2.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11266.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11266"},{"type":"ADVISORY","url":"https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-345-01"},{"type":"FIX","url":"https://github.com/malaterre/GDCM/commit/5829c95c8ac3afa9a3a3413675e948959c28a789"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/malaterre/gdcm","events":[{"introduced":"0"},{"fixed":"5829c95c8ac3afa9a3a3413675e948959c28a789"},{"fixed":"2d66f14563fb5e32fd538744f6c9fe532ddd3526"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.0.24"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v3.2.1","v3.2.0","v3.1.0","v2.0.18","v2.0.17","v2.0.16","v2.0.12","v2.0.7","v2.0.5","v2.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11266.json","vanir_signatures_modified":"2026-08-12T15:13:36Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"14508277489847140881181178753801618218","length":3699},"id":"CVE-2025-11266-43ad6b8e","signature_type":"Function","signature_version":"v1","source":"https://github.com/malaterre/gdcm/commit/5829c95c8ac3afa9a3a3413675e948959c28a789","target":{"file":"Source/DataStructureAndEncodingDefinition/gdcmSequenceOfFragments.h","function":"ReadValue"}},{"source":"https://github.com/malaterre/gdcm/commit/5829c95c8ac3afa9a3a3413675e948959c28a789","target":{"file":"Source/DataStructureAndEncodingDefinition/gdcmSequenceOfFragments.h"},"deprecated":false,"digest":{"line_hashes":["3584130573601150422239773274888427963","129083064797078902253931115651571964786","181374703737913879988987868105724939906","217182343023067882888346861882490080915"],"threshold":0.9},"id":"CVE-2025-11266-abfd1296","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N"}]}