Description:
A vulnerability was identified in DCMTK up to 3.6.9. This affects an
unknown function in the library
dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img.
Such manipulation leads to memory corruption. Local access is required
to approach this attack. The name of the patch is 7ad81d69b. It is best
practice to apply a patch to resolve this issue.
- https://bugs.mageia.org/show_bug.cgi?id=34718
- https://lists.debian.org/debian-lts-announce/2025/11/msg00006.html
- https://www.cve.org/CVERecord?id=CVE-2025-9732
- 9/core/dcmtk-3.6.7-4.6.mga9
Get the latest Linux and open source security news straight to your inbox.