SySS discloses five unpatched flaws in GDCM 3.3.0
SySS disclosed five unpatched GDCM 3.3.0 flaws—two stack overflows, two integer overflows, and one format-string bug—with no CVEs.
Full Disclosure carried five SySS advisories on Grassroots DICOM (GDCM) 3.3.0, the version SySS tested. SYSS-2026-067 and SYSS-2026-068 are stack-based buffer overflows (CWE-121) rated high; SYSS-2026-069 and SYSS-2026-070 are integer overflows (CWE-190) also rated high; SYSS-2026-071 is a format-string issue (CWE-134) rated medium. The GDCM Project was notified on 2026-07-24 and the flaws were publicly disclosed on 2026-09-23. No fixes are available, solution status remains open, and no CVE identifiers have been assigned. The advisories do not report exploitation. Sources agree on version, dates, and ratings, except that the SYSS-2026-067 note attributes the high rating to the vendor while the other advisories attribute ratings to SySS.
- Grassroots DICOM (GDCM) 3.3.0 is the affected and tested version in all five SySS advisories.
- SYSS-2026-067 and SYSS-2026-068 are stack-based buffer overflows (CWE-121), rated high, with no CVE and no fix.
- SYSS-2026-069 and SYSS-2026-070 are integer overflows (CWE-190), rated high, with solution status open and no CVE.
- SYSS-2026-071 is a format-string flaw (CWE-134), rated medium, with no fix and no CVE.
- The GDCM Project was notified on 2026-07-24; public disclosure was 2026-09-23; Full Disclosure items are dated 2026-09-27.
- The advisories do not report observed or in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 8h ago[SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)
Full Disclosure· 46
SySS disclosed an unpatched stack-based buffer overflow in GDCM 3.3.0, with no CVE assigned.
- · 8h ago[SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)
Full Disclosure· 52
SySS disclosed an unpatched stack-based buffer overflow in GDCM 3.3.0, a Grassroots DICOM library.
- · 8h ago[SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190)
Full Disclosure· 44
SySS disclosed a second unpatched high-risk integer overflow, SYSS-2026-069, in GDCM 3.3.0.