CVE-2025-48429 Details
Description
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability.
A vulnerability allowing out-of-bounds read has been identified in Grassroot DICOM version 3.024, specifically within the RLECodec::DecodeByStreams function. This vulnerability arises from improper size checks, enabling a specially crafted DICOM file to be processed in a way that leaks heap data. The issue occurs when the function fails to verify that memory accesses remain within the bounds of the source buffer, leading to potential exposure of sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2214 | CVE | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2214 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| malaterre grassroots dicom | 3.0.24 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 7, 2026 | Initial Analysis | [email protected] |
| Dec 16, 2025 | CVE Modified | CVE |
| Dec 16, 2025 | New CVE Received | [email protected] |