Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 42 python-pydicom Moderate Path Traversal Risk CVE-2026-32711

fedora
Calendar Grey April 9, 2026
Dist Fedora Esm H88
A patch for CVE-2026-32711 in python-pydicom to fix a path traversal issue in Fedora 42 provides essential protection.
Patch release for security advisory CVE-2026-32711

Summary

pydicom is a pure python package for working with DICOM files. It was made for

inspecting and modifying DICOM data in an easy "pythonic" way. The

modifications can be written again to a new file.

pydicom is not a DICOM server, and is not primarily about viewing images. It is

designed to let you manipulate data elements in DICOM files with python code.

Limitations -- the main limitation of the current version is that compressed

pixel data (e.g. JPEG) cannot be altered in an intelligent way as it can for

uncompressed pixels. Files can always be read and saved, but compressed pixel

data cannot easily be modified.

Documentation is available at https://pydicom.github.io/pydicom

Update Information:

Patch release for security advisory CVE-2026-32711. A crafted DICOMDIR could create a path traversal by setting ReferencedFileID to a path outside the File-set root.

Change Log

* Tue Mar 31 2026 Packit - 3.0.2-1 - Update to 3.0.2 upstream release - Resolves: rhbz#2449267 * Sat Jan 17 2026 Fedora Release Engineering - 3.0.1-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Sep 19 2025 Python Maint - 3.0.1-12 - Rebuilt for Python 3.14.0rc3 bytecode * Fri Aug 15 2025 Python Maint - 3.0.1-11 - Rebuilt for Python 3.14.0rc2 bytecode * Fri Jul 25 2025 Fedora Release Engineering - 3.0.1-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Fri Jun 6 2025 Python Maint - 3.0.1-9 - Rebuilt for Python 3.14

References


[ 1 ] Bug #2449267 - python-pydicom-3.0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2449267

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f89e555af4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-pydicom
Product: Fedora 42
Version: 3.0.2
Release: 1.fc42
Summary: Read, modify and write DICOM files with python code

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here