[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)
SySS disclosed an unpatched stack-based buffer overflow in GDCM 3.3.0, a Grassroots DICOM library.
Full Disclosure published SySS advisory SYSS-2026-068 describing a stack-based buffer overflow (CWE-121) in GDCM (Grassroots DICOM) version 3.3.0, which was tested. The GDCM Project was notified on 2026-07-24 and the issue was publicly disclosed on 2026-09-23. No CVE has been assigned and the solution status remains open, so no fix is available. The advisory rates the risk as high and does not report observed exploitation.
- Stack-based buffer overflow (CWE-121) in GDCM 3.3.0
- Advisory SYSS-2026-068; no CVE assigned yet
- Vendor notified 2026-07-24; disclosed 2026-09-23
- Solution status remains open; risk rated high
Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-068 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Tested Version(s): 3.3.0 Vulnerability Type: Stack-based Buffer Overflow (CWE-121) Risk Level: High Solution Status: Open Manufacturer Notification: 2026-07-24 Public Disclosure: 2026-09-23 CVE Reference: Not yet assigned...
This source does not provide full text. Read it at seclists.org.