Vulnerability Description
An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orthanc-Server | Orthanc | < 1.12.11 |
Related Weaknesses (CWE)
References
- https://kb.cert.org/vuls/id/536588Third Party AdvisoryVDB Entry
- https://www.machinespirits.de/Not Applicable
- https://www.orthanc-server.com/Product
FAQ
What is CVE-2026-5441?
CVE-2026-5441 is a vulnerability with a CVSS score of 7.1 (HIGH). An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression forma...
How severe is CVE-2026-5441?
CVE-2026-5441 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5441?
Check the references section above for vendor advisories and patch information. Affected products include: Orthanc-Server Orthanc.