CVE-2026-5441: Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)

Published Apr 9, 2026
·
Updated

An out-of-bounds read vulnerability exists in the DecodePsmctRle1 function of DicomImageDecoder.cpp. The PMSCTRLE1 decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.

Affected Software

1 affected component
Orthanc-server Orthanc<1.12.11

Event History

Apr 9, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 24, 58257
Event
via FIRST·09:37 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-5441?

CVE-2026-5441 has a moderate severity rating due to potential exploitation leading to information leaks.

2

How do I fix CVE-2026-5441?

To fix CVE-2026-5441, update to the latest version of Orthanc server that addresses the out-of-bounds read vulnerability.

3

What software is affected by CVE-2026-5441?

CVE-2026-5441 affects versions of Orthanc server prior to 1.12.11.

4

What is the impact of CVE-2026-5441?

The impact of CVE-2026-5441 includes potential unauthorized access to sensitive information due to out-of-bounds reads.

5

Is CVE-2026-5441 an easily exploitable vulnerability?

CVE-2026-5441 may require specific conditions to be exploited, making it moderately difficult to exploit without proper knowledge.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203