CVE-2025-11266

MEDIUM

Grassroots DICOM < - Buffer Overflow

Title source: llm
STIX 2.1

Description

An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an out-of-bounds memory access due to unsigned integer underflow in buffer indexing. It is exploitable via file input, simply opening a crafted malicious DICOM file is sufficient to trigger the crash, resulting in a denial-of-service condition.

Scores

CVSS v3 6.6
EPSS 0.0012
EPSS Percentile 2.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (3)
Grassroots/DICOM (GDCM) < 3.0.24
medInria/medInria < 4.0
NumFocus/SimpleITK < 2.5.2
Published Dec 12, 2025
Tracked Since Feb 18, 2026