|
|
Log in / Subscribe / Register

Debian alert DLA-4652-1 (gdcm)

From:  Emmanuel Arias <eamanu@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4652-1] gdcm security update
Date:  Fri, 26 Jun 2026 17:39:29 -0300
Message-ID:  <aj7jgRCBfBO9B9_1@debian>

------------------------------------------------------------------------- Debian LTS Advisory DLA-4652-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emmanuel Arias June 26, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : gdcm Version : 3.0.8-2+deb11u1 CVE ID : CVE-2024-22373 CVE-2024-22391 CVE-2024-25569 CVE-2025-11266 CVE-2025-48429 CVE-2025-52582 CVE-2025-53618 CVE-2025-53619 CVE-2026-3650 Debian Bug : 1070387 1122862 1123576 1123587 1123589 1132042 Multiple vulnerabilities were discovered in gdcm, a C++ library for working with DICOM medical files: CVE-2024-22373 An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. CVE-2024-22391 A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. CVE-2024-25569 An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability. CVE-2025-11266 An out-of-bounds write vulnerability exists in the parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an out-of-bounds memory access due to an unsigned integer underflow in buffer indexing. It is exploitable via file input: simply opening a crafted malicious DICOM file is sufficient to trigger the crash, resulting in a denial-of-service condition. CVE-2025-48429 An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability. CVE-2025-52582 An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. CVE-2025-53618 An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. The function grayscale_convert is called based on the value of the malicious DICOM file specifying the intended interpretation of the image pixel data. CVE-2025-53619 An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. The function null_convert is called based on the value of the malicious DICOM file specifying the intended interpretation of the image pixel data. CVE-2026-3650 A memory leak exists when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it. For Debian 11 bullseye, these problems have been fixed in version 3.0.8-2+deb11u1. We recommend that you upgrade your gdcm packages. For the detailed security status of gdcm please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gdcm Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmo+44AACgkQ+p3sXeEc Y/HQUxAAhxBg4q8wvdZdTZmTnrjbCOhTSI/+wqiJIXrSQ8JCGjjq9t3EpNHr0E/Y t6+eZS7BUAIGMs9yxwMKQLiIvUL14O4JKCEk+WasS9OMN2LIzRcc9z0tjeRdjcT8 c5+GxNF1zuHOHAYyVogaMyRS6RJZSgrltJzp5SOWsD7q/QKq33fSkqXDM8c0I4uO j7wk+/jE2EUH0ENmQMq7Kc8LTCRT+avhWpYfLy2E7/PNaUOi2kwcY2N5wFIH9WXV VKC9g+bGqlAMiY2voXJgYNv/0lds6ik/yRvPfUHz3vu6HhgQbn6eM767OdnGnUMB c488M+qO3BMF1/QJrP7h9Hgmbu6Qkm7Kdx2N5ZHDzFe61ByjXWQir0iFrMEtuTDu Zg0FCDEn+Wc2Y1D5midF3aPvW3tD22u44Ton1gVZH+v+J0PczEd3Hq6LKtlnF3SR lQG/gAX3GJj1ukw2X4ki0RsSbOpi9SRN6gbUVr4DsH/+A220IWHIZL6KyYvHXGbD RIwOshFE9/HIM0J7ijnS7qMTKmbRvV3Rm2Anba0Ape8fEG3CE+nvzbQBcrkuuTLU 2JCHGVIWvAvSw+xR4bwNw81ocnMKI6NoYpgGqGN10agWlSZzRLcfhq/LHRa41M1G PK5HFtwPPw2AXr1dfrAxZJfgphZhKgIO4A//ZhSWVwx3l/JnhKs= =KpG5 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds