What is CVE-2026-17264?
CVE-2026-17264 is triggered by opening a crafted DICOM file with malicious JPEG-compressed pixel data, leading to an attacker-controlled heap out-of-bounds write. This may allow an attacker to remotely execute arbitrary code. Affected users should avoid opening DICOM files from untrusted sources and apply relevant software updates.
Azərbaycanca: CVE-2026-17264, xüsusi hazırlanmış DICOM faylındakı zərərli JPEG sıxışdırılmış piksəl məlumatı vasitəsilə heap out-of-bounds write zəifliyinə səbəb olur. Bu, təcavüzkara uzaqdan ixtiyari kod icra etməyə imkan verə bilər. İstifadəçilər təsdiqlənməmiş mənbələrdən DICOM fayllarını açmamaqlı və müvafiq proqram yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
How can I protect against CVE-2026-17264?
By avoiding opening DICOM files from untrusted sources and applying relevant software updates.
What is the root cause of CVE-2026-17264?
Malicious JPEG-compressed pixel data in a crafted DICOM file triggers a heap out-of-bounds write.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.