A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/536588 | Third Party Advisory VDB Entry |
| https://www.machinespirits.de/ | Not Applicable |
| https://www.orthanc-server.com/ | Product |
Configurations
History
14 Apr 2026, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.cert.org/vuls/id/536588 - Third Party Advisory, VDB Entry | |
| References | () https://www.machinespirits.de/ - Not Applicable | |
| References | () https://www.orthanc-server.com/ - Product | |
| CWE | CWE-787 | |
| CPE | cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:* | |
| First Time |
Orthanc-server
Orthanc-server orthanc |
14 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
09 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 15:16
Updated : 2026-04-14 20:19
NVD link : CVE-2026-5442
Mitre link : CVE-2026-5442
CVE.ORG link : CVE-2026-5442
JSON object : View
Products Affected
orthanc-server
- orthanc
CWE
CWE-787
Out-of-bounds Write
