CVE-2026-5441 PUBLISHED

Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)

Assigner: certcc
Reserved: 02.04.2026 Published: 09.04.2026 Updated: 09.04.2026

An out-of-bounds read vulnerability exists in the DecodePsmctRle1 function of DicomImageDecoder.cpp. The PMSCT_RLE1 decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.

Product Status

Vendor Orthanc
Product DICOM Server
Versions
  • affected from 0 to 1.12.10 (incl.)

References

Problem Types

  • CWE-125 Out-of-bounds Read