High severity7.5NVD Advisory· Published Mar 26, 2026· Updated Jun 17, 2026
CVE-2026-3650
CVE-2026-3650
Description
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Grassroots/Grassroots DICOM (GDCM)v5Range: 3.2.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.