CVE-2026-44035: Uncontrolled recursion in DCMTK DICOMDIR parsing allows denial of service
Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OFFIS DCMTKto a version that resolves this vulnerability.Patch ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f
Event History
Frequently Asked Questions
Which applications should be prioritized for remediation?
Any application that opens DICOMDIR files using DCMTK is affected. This includes dcmgpdir and media viewers built on DCMTK.
What does exploitation require?
An attacker must provide a crafted DICOMDIR containing a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. A user or application must then open that file.
What fix is available?
The issue is fixed in DCMTK commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.