CVE-2026-50254: OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50254?
The severity of CVE-2026-50254 is rated high with a score of 7.5.
How do I fix CVE-2026-50254?
To fix CVE-2026-50254, update to the latest version of the OFFIS DCMTK Toolkit that addresses this vulnerability.
What type of attack does CVE-2026-50254 enable?
CVE-2026-50254 enables an unauthenticated remote attacker to perform a memory leak attack by sending crafted connection requests.
What impact does CVE-2026-50254 have on the service?
CVE-2026-50254 causes the memory usage of the service to grow quickly, potentially leading to a crash and stopping the service from accepting connections.
Is authentication required to exploit CVE-2026-50254?
No, CVE-2026-50254 can be exploited by unauthenticated remote attackers.