[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)
SySS disclosed a second unpatched high-risk integer overflow, SYSS-2026-069, in GDCM 3.3.0.
SySS advisory SYSS-2026-069 describes a distinct integer overflow (CWE-190) in the GDCM Grassroots DICOM library, affecting tested version 3.3.0. Risk is rated high and the solution status is open. The GDCM Project was notified on 2026-07-24 and the flaw was publicly disclosed on 2026-09-23. No CVE has been assigned and active exploitation is not mentioned.
- Separate integer overflow tracked as SYSS-2026-069.
- GDCM 3.3.0 is the affected and tested version.
- Risk is high and no solution is available.
- CVE reference is not yet assigned.
- Disclosed publicly on 2026-09-23 after a July notification.
Posted by Matthias Deeg via Fulldisclosure on Sep 26 Advisory ID: SYSS-2026-069 Product: GDCM (Grassroots DICOM) Manufacturer: GDCM Project Affected Version(s): 3.3.0 Tested Version(s): 3.3.0 Vulnerability Type: Integer Overflow (CWE-190) Risk Level: High Solution Status: Open Manufacturer Notification: 2026-07-24 Public Disclosure: 2026-09-23 CVE Reference: Not yet assigned Author of...
This source does not provide full text. Read it at seclists.org.