A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grassroots
Grassroots grassroots Dicom |
|
| Vendors & Products |
Grassroots
Grassroots grassroots Dicom |
Fri, 27 Mar 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 26 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it. | |
| Title | Grassroots DICOM Missing release of memory after effective lifetime | |
| Weaknesses | CWE-401 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-03-26T21:10:30.864Z
Reserved: 2026-03-06T16:24:00.662Z
Link: CVE-2026-3650
No data.
Status : Received
Published: 2026-03-26T22:16:31.370
Modified: 2026-03-26T22:16:31.370
Link: CVE-2026-3650
OpenCVE Enrichment
Updated: 2026-03-27T09:23:15Z