An out-of-bounds read vulnerability exists in the...
High severity
Unreviewed
Published
Dec 17, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2026
Description
Published by the National Vulnerability Database
Dec 16, 2025
Published to the GitHub Advisory Database
Dec 17, 2025
Last updated
Jan 2, 2026
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function
grayscale_convertis called based of the value of the malicious DICOM file specifying the intended interpretation of the image pixel dataReferences