CVE-2026-44038

Source
https://cve.org/CVERecord?id=CVE-2026-44038
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44038.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44038
Downstream
Published
2026-10-08T13:17:17Z
Modified
2026-10-10T07:05:55Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A global out-of-bounds read in the Huffman decoder of the bundled IJG JPEG libraries (dcmjpeg/libijg8, libijg12 and libijg16) of OFFIS DCMTK 3.7.0 allows an attacker to read memory beyond the extend_test[] and extend_offset[] tables, causing incorrectly decoded pixel data or a crash, via a DICOM file with a crafted JPEG stream whose Huffman table defines a difference category above 15. Huffman symbol values are not range-checked unless DCMTK is built with DCMTK_ENABLE_STRICT_HUFFMAN_TABLE_CHECK, which is disabled by default. dcmdjpeg and any application that decompresses JPEG DICOM images with DCMTK are affected. The issue is fixed in commit d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5.

References

Affected packages

Git / github.com/dcmtk/dcmtk

Affected ranges

Type
GIT
Repo
https://github.com/dcmtk/dcmtk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

CAR96-3.*
CAR96-3.0.1
CAR96-3.0.2
DCMTK-3.*
DCMTK-3.1.0
DCMTK-3.1.1
DCMTK-3.1.2
DCMTK-3.2.0
DCMTK-3.2.1
DCMTK-3.3.0
DCMTK-3.3.1
DCMTK-3.4.0
DCMTK-3.4.1
DCMTK-3.4.2
DCMTK-3.5.0
DCMTK-3.5.1
DCMTK-3.5.2
DCMTK-3.5.2a
DCMTK-3.5.3
DCMTK-3.5.4
DCMTK-3.6.0
DCMTK-3.6.1_20110225
DCMTK-3.6.1_20110519
DCMTK-3.6.1_20110707
DCMTK-3.6.1_20110922
DCMTK-3.6.1_20111208
DCMTK-3.6.1_20120222
DCMTK-3.6.1_20120515
DCMTK-3.6.1_20120831
DCMTK-3.6.1_20121102
DCMTK-3.6.1_20131114
DCMTK-3.6.1_20140617
DCMTK-3.6.1_20150217
DCMTK-3.6.1_20150629
DCMTK-3.6.1_20150924
DCMTK-3.6.1_20160216
DCMTK-3.6.1_20160630
DCMTK-3.6.1_20161102
DCMTK-3.6.1_20170228
DCMTK-3.6.2
DCMTK-3.6.3
DCMTK-3.6.4
DCMTK-3.6.5
DCMTK-3.6.5+_20191213
DCMTK-3.6.6
DCMTK-3.6.7
DCMTK-3.6.8
DCMTK-3.6.9
DCMTK-3.7.0
Other
latest

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44038.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "170224089103582227029923350330518948086",
                "237319796681969543720267715624709924845",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "223058330846531244729124936326145813684",
                "260902634031194533683468794494166464310"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-13d85098",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdshuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "125234630022618454100880350039023633718",
                "251909564100242552155886323834352600506",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "159818325274635626437917651130140710710",
                "326263968123480069512585931305965911176"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-237e7ebe",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdphuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "159991825021739021990634430338027037038",
            "length": 1385
        },
        "id": "CVE-2026-44038-3441313d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdlhuff.c",
            "function": "decode_mcus"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "159991825021739021990634430338027037038",
            "length": 1385
        },
        "id": "CVE-2026-44038-4e6f4031",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdlhuff.c",
            "function": "decode_mcus"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "50250525439352053178242379481829429016",
            "length": 1232
        },
        "id": "CVE-2026-44038-516dc59b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdphuff.c",
            "function": "decode_mcu_DC_first"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "315774238913414956536207464918644281915",
                "305154871510946020204997784587759407152",
                "100697793669319324000764714276660465261",
                "129788758919199506167048050571869543301",
                "23325219694734154586012800198945528887"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-564d95ab",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdlhuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "293518764266177619031901973641757237806",
            "length": 1921
        },
        "id": "CVE-2026-44038-6b949cba",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdshuff.c",
            "function": "decode_mcu"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "278836621381420932542013635104149969767",
            "length": 1806
        },
        "id": "CVE-2026-44038-6e7c8359",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdshuff.c",
            "function": "decode_mcu"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "170224089103582227029923350330518948086",
                "237319796681969543720267715624709924845",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "223058330846531244729124936326145813684",
                "260902634031194533683468794494166464310"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-772fb356",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdshuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "287681774361874935838109145641017120881",
            "length": 1887
        },
        "id": "CVE-2026-44038-78b34320",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdlhuff.c",
            "function": "decode_mcus"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "100038949287673236790057812374518188105",
                "92546057002073363474291344576667105595",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "159818325274635626437917651130140710710",
                "326263968123480069512585931305965911176"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-902abed2",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdphuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "315013473697190718544975112090498254837",
                "83757381446180678670818497428230233374",
                "68336538335244328378864236131607196829",
                "129788758919199506167048050571869543301",
                "23325219694734154586012800198945528887"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-99fcead7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdlhuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "278836621381420932542013635104149969767",
            "length": 1806
        },
        "id": "CVE-2026-44038-9edf7f2e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdshuff.c",
            "function": "decode_mcu"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "331862017919413752948560187156897899455",
                "295262371278682814622287337162486323698",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "223058330846531244729124936326145813684",
                "260902634031194533683468794494166464310"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-a66fdb87",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg16/jdshuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "131398697852104318910022292156266009149",
            "length": 1129
        },
        "id": "CVE-2026-44038-abd25c80",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg12/jdphuff.c",
            "function": "decode_mcu_DC_first"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "125234630022618454100880350039023633718",
                "251909564100242552155886323834352600506",
                "109336430897402465039660023792233558254",
                "297269115982512659977221391455876890449",
                "159818325274635626437917651130140710710",
                "326263968123480069512585931305965911176"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-dcc3874d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdphuff.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "131398697852104318910022292156266009149",
            "length": 1129
        },
        "id": "CVE-2026-44038-e4f8d07d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdphuff.c",
            "function": "decode_mcu_DC_first"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "315774238913414956536207464918644281915",
                "305154871510946020204997784587759407152",
                "100697793669319324000764714276660465261",
                "129788758919199506167048050571869543301",
                "23325219694734154586012800198945528887"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-44038-efa37dbd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dcmtk/dcmtk/commit/d6ae1bc8d5b9ae9c7300013c8c85cc2ea0fd8cf5",
        "target": {
            "file": "dcmjpeg/libijg8/jdlhuff.c"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:05:55Z"