CVE-2026-17264: Medixant RadiAnt DICOM Out-of-bounds write
Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Medixant RadiAnt DICOMto a version that resolves this vulnerability.Fixed in 2026.1 - Compensating control
Open DICOM files only from trusted and reliable sources.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17264?
CVE-2026-17264 has a medium severity score of 4.3.
How do I fix CVE-2026-17264?
To mitigate CVE-2026-17264, ensure that you are using the latest version of Medixant RadiAnt DICOM that addresses this vulnerability.
What is the impact of CVE-2026-17264?
CVE-2026-17264 can allow an attacker to remotely execute arbitrary code by exploiting an out-of-bounds write when opening specific crafted DICOM files.
Who is affected by CVE-2026-17264?
Users of Medixant RadiAnt DICOM software are affected by CVE-2026-17264 if they open specially crafted DICOM files.
When was CVE-2026-17264 published?
CVE-2026-17264 was published on August 6, 2026.