CVE-2026-3650
Grassroots DICOM Missing release of memory after effective lifetime
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it.
Coverage 1 source
-
2026-03-24
CISA Cybersecurity Advisories
critical
Grassroots DICOM (GDCM)
Grassroots DICOM (GDCM) 3.2.2 has a denial-of-service vulnerability (CVE-2026-3650, CVSS 7.5).
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands